Hi, > Personally think that clear text is bad as anyone intercepting the > packets can easily pick up anything in clear text.
You mean intercepting the packets between LDAP server and RADIUS server (since the communication with the RADIUS client isn't affected anyway)? But knowing the LM or NT password is sufficient to log in anyway, if you spend some minutes to modify some open source client accordingly , isn't it? You don't need the clear text password anyway in Windows' authentications scheme, AFAICT, so what's the point? Regards, Stefan - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html