> On Jul 20, 2017, at 09:10, Kylián Martin via PacketFence-users 
> <[email protected]> wrote:
> 
> Hi everyone,
> 
> I would like to use packetfence for 802.1x PEAP / EAP-MSchapv2 wireless 
> authentication. (And other features)
> But I do not want to use the AD binding (as it is now). For security reasons, 
> I want to use local SQL and authenticate users there.
> (Can I insert users to local sql with my own application correctly?)
> 
> The question is - what password encryption can I use in local SQL?
> If I want to use EAP-mschapv2, my password should be a plaintext or NT hash.
> (http://deployingradius.com/documents/protocols/compatibility.html)
> Of course, I'd like to see the passwords as bcrypt. I'am afraid it won't work 
> then.


Your only options are plaintext or NT hashes.
That's a limitation of the protocol, not of PacketFence (or FreeRADIUS in 
general).

There's no way around that.

Regards,
--
Louis Munro
[email protected] <mailto:[email protected]>  ::  www.inverse.ca 
<http://www.inverse.ca/> 
+1.514.447.4918 x125  :: +1 (866) 353-6153 x125
Inverse inc. :: Leaders behind SOGo (www.sogo.nu <http://www.sogo.nu/>) and 
PacketFence (www.packetfence.org <http://www.packetfence.org/>)
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to