<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=5&amp;t=811" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2012-05-15T15:41:48+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=5&amp;t=811</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2012-05-15T15:41:48+01:00</updated>
<published>2012-05-15T15:41:48+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=811&amp;p=3095#p3095</id>
<link href="https://forum.yubico.com/viewtopic.php?t=811&amp;p=3095#p3095"/>
<title type="html"><![CDATA[Returning of group membership information in YubiRADIUS]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=811&amp;p=3095#p3095"><![CDATA[
Recently we have received a few mails asking about how YubiRADIUS returns the group membership information of the user.<br /><br />YubiRADIUS returns user's group membership information as RADIUS attribute = 25 i.e. &quot;CLASS&quot;.<br /><br />If you wish you use this information in the authentication process by your client, you should<br /><br />a) YRVA configuration:<br /><br />1. You need to enable the 'Return user's Group Membership in RADIUS response’. <br /><br />Typically 'Response format' is set as:<br /><br />'cn= &lt;Group name&gt;;' (without quotes)<br /><br />Goto “YubiRADIUS Virtual Appliance” &gt;&gt; Under “Domain” TAB select “domain name” &gt;&gt; Select “Configuration” &gt;&gt; Enable “Return user's Group Membership in RADIUS response” &gt;&gt; Enter group information in “Response format” as,<br /><br />“cn= “&lt;Group name&gt;”;”<br /><br />Under “Group return information” select which ever is required either “Group DN” or “Group Name”<br /><br />2. You can add client as per device IP and the client secret.<br /><br /><br />b) set the RADIUS attribute to 25 or CLASS in your device's configuration (please refer to user guide of your device for more details).<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Tue May 15, 2012 3:41 pm</p><hr />
]]></content>
</entry>
</feed>