Update on MS-CHAP Authentication / Bug 17

2009-10-06 Thread Garber, Neal
applied (for about 6 weeks now) to two of our FR servers and haven't seen any issues. Neal -Original Message- From: Garber, Neal Sent: Friday, October 02, 2009 1:58 AM To: 'Marco D'Ettorre' Subject: RE: MS-CHAP Authentication / Bug 17 Thank you for sharing your experience Marco. At some

Re: Update on MS-CHAP Authentication / Bug 17

2009-10-06 Thread Alan DeKok
Garber, Neal wrote: Here's some feedback I received (off-list) regarding the patch for bug 17.. I received an E-mail from someone experiencing the userid case sensitivity issue with EAP/MS-CHAPv2 in FR. He applied the patch attached to bug 17 and confirmed that it fixed the problem for

MS-CHAP Authentication / Bug 17

2009-09-21 Thread Garber, Neal
I've been running 2.1.6 in Production with the patch from Bug 17, for a month, and everything has been working fine. As a reminder, this patch corrects a bug in MS-CHAP with the calculation of the MS-CHAPv1 challenge passed to ntlm_auth. It causes inappropriate Logon Failure errors, in

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Alan Buxey
Hi, has a look at this but it's only of interest for classic MS-CHAP activity rather than MSCHAPv2 in PEAP or TTLS - correct? (in this case we wouldnt use this function or be able to test this at our site...but logically it all looks sane) a few changes though (?) - its 'delimiter', not

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Johan Meiring
Alan Buxey wrote: Hi, has a look at this but it's only of interest for classic MS-CHAP activity rather than MSCHAPv2 in PEAP or TTLS - correct? (in this case we wouldnt use this function or be able to test this at our site...but logically it all looks sane) a few changes though (?) - its

RE: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Garber, Neal
Alan, Thank you for taking the time to review the patch and for your feedback. has a look at this but it's only of interest for classic MS-CHAP activity rather than MSCHAPv2 in PEAP or TTLS - correct? (in this case we wouldnt use this function or be able to test this at our site...but

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Alan Buxey
Hi, a few changes though (?) - its 'delimiter', not 'delimeter' ;-) and...some RDEBUG2 starts with a white space and others print tight to the line - reason for such differences? http://www.googlefight.com/index.php?lang=en_GBword1=delimiterword2=delimeter your point is? (I win the

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Alan Buxey
Hi, Actually, the problem definitely impacts PEAP/MSCHAPv2 (and I believe TTLS/MSCHAPv2 also because it's an error in MS-CHAP, but we don't use TTLS so I can't test that). (I haven't thought about it enough to know whether it affects v1, but it definitely occurs with v2 as that's where I

RE: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Garber, Neal
hmm, okay - I'll only be able to introduce core systrems with this patch in place after 2nd October - we currently have a change freeze on main systems until then That's fabulous. Thanks for your time and willingness to test. - List info/subscribe/unsubscribe? See

RE: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Garber, Neal
google search for 'define:delimeter' Did you mean: define:delimiter Top 2 results shown :-) You are clearly correct given the root of the word delimiter is delimit (not delimet) :-) - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Johan Meiring
Alan Buxey wrote: Hi, a few changes though (?) - its 'delimiter', not 'delimeter' ;-) and...some RDEBUG2 starts with a white space and others print tight to the line - reason for such differences? http://www.googlefight.com/index.php?lang=en_GBword1=delimiterword2=delimeter your point

Re: MS-CHAP Authentication / Bug 17

2009-09-21 Thread Alan Buxey
Hi, http://www.googlefight.com/index.php?lang=en_GBword1=delimiterword2=delimeter your point is? (I win the fight ;-) ) Oops I (like an idiot) read you comment the wrong way around! 8-) thats okay - I've got a useful URL to settle arguments with now - thanks! :-) alan - List