Re: 802.1x -Radius -Ldap

2010-06-18 Thread Kyle Plimack
, John Dennis jden...@redhat.com wrote: On 06/18/2010 02:01 AM, Alan DeKok wrote: Kyle Plimack wrote: I have pap working (i.e. I ran radtest and got an access-accept). I don't want to configure certs on each of my hosts for each of my clients, so I'd like to use PEAP/msChapV2 so that dot1x clients

Re: 802.1x -Radius -Ldap

2010-06-18 Thread Kyle Plimack
So how do I get pap to do it? On 6/18/10 12:50 PM, Alan DeKok al...@deployingradius.com wrote: Kyle Plimack wrote: I added an entry to ldap.attrmap, checkItem Cleartext-Password userPassword The Password is not cleartext, but I read somewhere that radius is supposed to figure that out

Re: 802.1x -Radius -Ldap

2010-06-18 Thread Kyle Plimack
the best explanation of how FreeRADIUS processes requests I've ever heard... :) -Arran On Jun 18, 2010, at 1:50 PM, John Dennis wrote: On 06/18/2010 04:03 PM, Kyle Plimack wrote: So how do I get pap to do it? If you're asking how to you get pap to do mschap then that's a nonsensical

Re: 802.1x -Radius -Ldap

2010-06-17 Thread Kyle Plimack
I have pap working (i.e. I ran radtest and got an access-accept). I don't want to configure certs on each of my hosts for each of my clients, so I'd like to use PEAP/msChapV2 so that dot1x clients are prompted for and username/password. According the the deployingradius.com guide, once pap is