NT DOMAIN AUTHENTICATION

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
PeterG
Posts: 3
Joined: Wed Sep 07, 2016 1:02 pm

NT DOMAIN AUTHENTICATION

Post by PeterG » Wed Sep 07, 2016 1:36 pm

Greetings,

Trying to authenticate users in AD.
Im running SoftEther v4.20 on Linux Debian which is joined to AD (win 2012).

I have created an user in SoftEther and mapped it to nt domain authentication.

When the authentication is being initiated I see the following SoftEther logs:

2016-09-07 13:30:54.458 [HUB "xxxxxx"] The connection "CID-68" (IP address: xxxx.xxxx.xxxx.xxxx, Host name: xxxxx-xxxx-xxxx.xxxxxx.xx, Port number: 54379, Client name: "Microsoft SSTP VPN Client", Version: 4.20, Build: 9608) is attempting to connect to the Virtual Hub. The auth type provided is "External server authentication" and the user name is "xxxxxxx".
2016-09-07 13:30:54.458 [HUB "xxxxxx"] Connection "CID-68": User authentication failed. The user name that has been provided was "xxxxxxx".
2016-09-07 13:30:54.489 Connection "CID-68" terminated by the cause "User authentication failed." (code 9).


Did anybody have a chance to implement nt domain authentication of SoftEther running on Linux that is joined to AD ?

Thanks in advance,
Peter

PeterG
Posts: 3
Joined: Wed Sep 07, 2016 1:02 pm

Re: NT DOMAIN AUTHENTICATION

Post by PeterG » Fri Sep 09, 2016 12:34 pm

Greetings,

I went to documentation and found that nt domain authentication doesnt work on Linux

here are the details


In order to conduct NT domain or Active Directory authentication, the SoftEther VPN Server to conduct user authentication must be capable of running on Windows NT, with capable of participating in domain. SoftEther VPN Servers that run on Windows 98, Windows 98 Second Edition, Windows Millennium Edition or Linux, FreeBSD, Solaris or Macintosh OS X cannot conduct NT domain or Active Directory authentication. VPN Server cannot authenticate the NT domain or Active Directory. In this case, while authentication method is set to “NT domain” or “Active Directory” domain, authentication does not work.

https://www.softether.org/4-docs/1-manu ... entication

Thanks,
Peter

PeterG
Posts: 3
Joined: Wed Sep 07, 2016 1:02 pm

Re: NT DOMAIN AUTHENTICATION

Post by PeterG » Mon Sep 12, 2016 1:54 pm

I tested nt domain authentication on windows server 2012 r2 and it works well.

Thanks,
Peter

desperados
Posts: 41
Joined: Tue May 20, 2014 10:15 am

Re: NT DOMAIN AUTHENTICATION

Post by desperados » Mon Oct 24, 2016 7:27 am

my domain is managed by a linux server, not a windows one
can I use domain authentication in some way?
thanks

desperados
Posts: 41
Joined: Tue May 20, 2014 10:15 am

Re: NT DOMAIN AUTHENTICATION

Post by desperados » Sat Oct 29, 2016 7:37 am

desperados wrote:
> my domain is managed by a linux server, not a windows one
> can I use domain authentication in some way?
> thanks

maybe using LDAP ?

moatazelmasry
Posts: 336
Joined: Sat Aug 15, 2015 7:41 pm

Re: NT DOMAIN AUTHENTICATION

Post by moatazelmasry » Sun Oct 30, 2016 12:01 pm

if you are not bound to windows like the OP, why don't you just use freeradius?

If you must use LDAP, you can configure freeradius to have LDAP as its backend I think

desperados
Posts: 41
Joined: Tue May 20, 2014 10:15 am

Re: NT DOMAIN AUTHENTICATION

Post by desperados » Tue Nov 08, 2016 8:05 am

desperados wrote:
> my domain is managed by a linux server, not a windows one
> can I use domain authentication in some way?
> thanks

and what if I install Softether in a Windows Server joined to my linux domain?

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: NT DOMAIN AUTHENTICATION

Post by thisjun » Mon Nov 28, 2016 6:02 am

>and what if I install Softether in a Windows Server joined to my linux domain?

It may be possible.

Post Reply