Caching techniques with ntlm_auth usage? (EAP-PEAP-MSchapV2)

2011-03-04 Thread John Douglass
Group, Recently, my AD servers were patched by another support group and this caused a (small but noticeable) service outage for our WPA radius services (Radius 2.1.9) I am curious how others who are using AD as their backends have either configured smb.conf/winbind/radius in order to do

Re: Caching techniques with ntlm_auth usage? (EAP-PEAP-MSchapV2)

2011-03-04 Thread Gary Gatten
with ntlm_auth usage? (EAP-PEAP-MSchapV2) Group, Recently, my AD servers were patched by another support group and this caused a (small but noticeable) service outage for our WPA radius services (Radius 2.1.9) I am curious how others who are using AD as their backends have either configured smb.conf

Re: Caching techniques with ntlm_auth usage? (EAP-PEAP-MSchapV2)

2011-03-04 Thread Phil Mayers
On 03/05/2011 12:21 AM, Gary Gatten wrote: I kinda like your caching idea, but not sure of any security implications. It's not a workable idea. MSCHAP responses are specific to the 8-byte random challenge, which is different every time. You can't cache them. I have (2) FR servers (each

Re: Caching techniques with ntlm_auth usage? (EAP-PEAP-MSchapV2)

2011-03-04 Thread James J J Hooper
--On 04 March 2011 12:34 -0500 John Douglass john.dougl...@oit.gatech.edu wrote: Group, Recently, my AD servers were patched by another support group and this caused a (small but noticeable) service outage for our WPA radius services (Radius 2.1.9) I can think of two things to