Re: Freeradius-Users digest, Vol 1 #4631 - 12 msgs

This is a discussion on Re: Freeradius-Users digest, Vol 1 #4631 - 12 msgs within the FreeRADIUS Users forums, part of the Networking and Network Related category; > > You can't use PEAP unless you have plaintext passwords stored in the > LDAP or NT/LM ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-19-2005
Matt McFarlane
 
Posts: n/a
Default Re: Freeradius-Users digest, Vol 1 #4631 - 12 msgs

>
> You can't use PEAP unless you have plaintext passwords stored in the
> LDAP or NT/LM password hashes. To use LDAP bind to authenticate you will
> need to use TTLS with PAP as inner tunnel authentication. This is how
> you can configure your clients to use TTLS+PAP
>


The passwords are revealed in plaintext. Would prefer to use PEAP w/MsChapv2 as
any XP client on our network will already have that.

Is there anything special to configure in the eap.conf. I used certs.sh to create the
demoCA which I'm using for testing.

Thanks.

eap.conf

eap {
default_eap_type = peap
timer_expire = 60
ignore_unknown_eap_types = no
cisco_accounting_username_bug = no

tls {
private_key_password = whatever
private_key_file = ${raddbdir}/certs/cert-srv.pem
certificate_file = ${raddbdir}/certs/cert-srv.pem
CA_file = ${raddbdir}/certs/demoCA/cacert.pem
dh_file = ${raddbdir}/certs/dh
random_file = ${raddbdir}/certs/random
}

peap {
default_eap_type = mschapv2
}
mschapv2 {
}
}



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:19 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0