EAP-TTLS inner auth methods for 802.1x

This is a discussion on EAP-TTLS inner auth methods for 802.1x within the FreeRADIUS Users forums, part of the Networking and Network Related category; I have configured a working EAP-TLS system and am now migrating to use EAP-TTLS (with both client side ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-29-2007
James Lever
 
Posts: n/a
Default EAP-TTLS inner auth methods for 802.1x

I have configured a working EAP-TLS system and am now migrating to
use EAP-TTLS (with both client side certificates and a password
authentication mechanism).

I'm stuck trying to work out how to avoid sending the password
unhashed to the server and think that some form of CHAP/MSCHAPv2
might be the right way to go. My current thoughts are that I should
use PAP with SHA1 or SSHA1 but I seem to get the right config (if it
is even possible).

So, with this problem, can anybody suggest a way to use SHA1/SSHA1 or
some other form of cryptographically secure, non-cleartext password
within the inner authentication mechanism of EAP-TTLS for use in WPA2
Enterprise/802.1x.

If this is feasible/possible, are there any gotcha's with the various
supplicants to getting this to work from the client side and avoiding
sending the passwords in cleartext (inside the EAP-TLS tunnel).

Also, while I'm here, any suggestions for an appropriate backend
password store so that there is never a cleartext password except for
the initial entry (password change) on the server side would be
appreciated.

cheers,
James



-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 11:56 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0