Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
PPTP server with NTLM auth failing...
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
The_Great_Sephiroth
Veteran
Veteran


Joined: 03 Oct 2014
Posts: 1343
Location: Fayetteville, NC, USA

PostPosted: Tue Oct 27, 2015 3:04 pm    Post subject: PPTP server with NTLM auth failing... Reply with quote

I have a PPTP server at a client location that is a domain member, but will not authenticate against a single group. I created an AD group "PPTP" and added a few accounts to it. On the command-line I can do the following.
Code:

ntlm_auth --require-membership-of="KIGM\PPTP" --username=vpnusername

It asks for the user's password then returns success (0). However, this does not work in my pptp-options.
Code:

name vpn01
domain kigm.local
refuse-pap
refuse-chap
refuse-mschap
require-mschap-v2
require-mppe-128
ms-dns 192.168.0.1
ms-dns 192.168.0.2
proxyarp
nodefaultroute
lock
nobsdcomp
plugin winbind.so
ntlm_auth-helper "/usr/bin/ntlm_auth --helper-protocol=ntlm-server-1 --require-membership-of=KIGM\\PPTP"

Once I add that, nobody can connect, but without it, every user can connect. We only want specific users using PPTP, so how can I correct this? The error on my client is that MSCAP authentication failed.

*UPDATE*

I removed the helper protocol parameter because when using it on the command-line it would hang. Now it just flat-out denies access to every user on the domain. If I remove the membership requirement, it works for everybody again. How can I limit this? It doesn't seem like it should be this difficult, but I have been stuck here since last week.
_________________
Ever picture systemd as what runs "The Borg"?
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum