Re: [RadiusNT] Weird RADIUS behavior.

Dale E. Reed Jr. ( (no email) )
Wed, 14 Jun 2000 17:25:07 -0700

Randy Martin wrote:
>
> Just thought I'd pass this along to the list. We are using Emerald and
> RadiusNT (both the latest versions) and needed to turn off a client's
> account today. We first set the expiration date to yesterday, but he was
> still able to login. Then we set both the service and the mbr to inactive.
> He still authenticated successfully. Then we changed the password on the
> account. He was STILL able to authenticate. I finally stopped and started
> the Radius service on the server. This finally corrected the problem, and
> he wasn't able to authenticate anymore. This is the first problem we've had
> with RadiusNT since starting to use it in February. This seems like pretty
> bizarre behavior to me, so I thought I ask if anyone else has ever seen
> anything like this?

You didn't say what version of RadiusNT you are running. RadiusNT 3.0
has a local cache that could cause this scenario. There are options you
can tune to tell it how long to keep a user in the cache before removing
them or updating them. There is also another option to tell it how
often to check for changes to the user information.

Since the cache is volatile by default, restarting the service would
clear the cache.

-- 

Dale E. Reed Jr. Emerald and RadiusNT/X__________________________________________IEA Software, Inc. www.iea-software.com

For more information about this list (including removal) go to:http://www.iea-software.com/support/maillists/liststart