Re: pap/peap confusion

This is a discussion on Re: pap/peap confusion within the FreeRADIUS Users forums, part of the Networking and Network Related category; Matt Ashfield wrote: > I'm pouring through the alphabet soup of all of this and have a few > ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-14-2007
Phil Mayers
 
Posts: n/a
Default Re: pap/peap confusion

Matt Ashfield wrote:
> I'm pouring through the alphabet soup of all of this and have a few
> questions that keep popping up.
>
> During a pap conversation, the radius server ends up with the
> username/password passed to it from the client. It then encrypts the
> password to match the encryption of the stored password in ldap (or other
> directory) and tries a bind. Correct?


Yes

>
> During a PEAP conversation, the radius server also would end-up with a
> username/password received from the client (either via clear-text or via the
> mschap conversation). Why can it not then encrypt the password just like PAP
> did? Does it do the comparison to LDAP stored passwords via MSCHAP as well?


No, miles off.

During a PEAP/MS-CHAP conversation, the server ends up with:

challenge == random bytes
response == HASH(challenge, HASH(password))

If the server has any of:

* the plaintext password
* HASH(password) i.e. the NT or LM hashes
* access to a domain controller which has the NT/LM hashes

....it can check the challenge and response match and that the client is
who they say they are.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:33 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0