Security

 View Only
  • 1.  IPA server authentication issues

    Posted Feb 19, 2025 11:44 PM

    I am playing around with an IPA server as LDAP and Domain server and for the live of .. can't get it to authenticate any users. 

    LDAP search in the format below works fine.

    ldapsearch -x -D "uid=user1,cn=users,cn=accounts,dc=mydomain,dc=auth" -W -H ldap://centos-9-server.mydomain.auth -b "cn=accounts,dc=mydomain,dc=auth"

    I can also add it as an ldap server or active directory and it it gets authenticated

    See below the LDAP browser output

    I tried every available authentication method but nothing seems to work both a Windows 11 and a Iphone (latest IOS) where used

    I am probably missing something, any help and guidance is appreciated. On a side note it is working with another active directory solution but not with FreeIPA. 
    Thanks


    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------


  • 2.  RE: IPA server authentication issues

    Posted Feb 20, 2025 10:07 AM

    How is the supplicant configured?  Your service has to match an auth method with how the client device supplicant is configured.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: IPA server authentication issues

    Posted Feb 21, 2025 08:42 AM

    Hi Carson,

     

    Thanks for the tip, eventually I came to the conclusion that the authentication methods of FREE IPA was missing PEAP/MSCHAP and I did not have EAP-TLS running, ran into a too many dependency issues and disbanded my effort. Although it is kind of a poor man's solution for now I just stick with the QNAP AD solution, which suffices in my effort to familiarize myself with Clearpass.

     

     

    Martijn van Overbeek
    Architect
    Work 443-333-5809
    Mobile 984-528-1279
    Email mvanoverbeek@blueally.com

     






  • 4.  RE: IPA server authentication issues

    Posted Mar 11, 2025 02:44 PM

    I wanted to follow up on this question. Although I haven't tested it again, I suspect that this was an oversight/error on my end. I did not join the domain which is I think required for MSChapv2 authentication with Clearpass



    ------------------------------
    Martijn van Overbeek
    Architect, Netcraftsmen a BlueAlly Company
    ------------------------------



  • 5.  RE: IPA server authentication issues

    Posted Mar 11, 2025 02:49 PM

    Yes, ClearPass must have a domain membership relationship with the targeted domain for MS-CHAPv2 to be used.  One of the benefits of moving to TLS is removing that requirement.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 6.  RE: IPA server authentication issues

    Posted Mar 11, 2025 02:54 PM

    Fully understand that, it is a bit more work setting up though, so that's why I wanted to start with the MS-CHAP solution.