Re: MS 8021.x PEAP failing - new info...

2009-08-21 Thread Gary Gatten
exact same info as the Xsupplicant is supposed to pull from the GINA / windows login? - Original Message - From: freeradius-users-bounces+ggatten=waddell@lists.freeradius.org To: FreeRadius users mailing list Sent: Fri Aug 21 11:14:05 2009 Subject: RE: MS 8021.x PEAP failing - new

RE: MS 8021.x PEAP failing - new info...

2009-08-21 Thread Ivan Kalik
> Check this out... I entered the Domain Name manually and it worked! > So, now I have no freaking clue... I thought it was something with the > "//" in the DomainName//UserName - but doesn't look like it. > > Here's some debug output. I snipped all the stuff before this output - > from what I

RE: MS 8021.x PEAP failing - new info...

2009-08-20 Thread Gary Gatten
Check this out... I entered the Domain Name manually and it worked! So, now I have no freaking clue... I thought it was something with the "//" in the DomainName//UserName - but doesn't look like it. Here's some debug output. I snipped all the stuff before this output - from what I can tell it

RE: MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
l@lists.freeradius.org [mailto:freeradius-users-bounces+ggatten=waddell@lists.freeradius.or g] On Behalf Of Garber, Neal Sent: Thursday, August 20, 2009 5:01 PM To: 'FreeRadius users mailing list' Subject: RE: MS 8021.x PEAP failing > Yup, that line is there. Much of the doc online is WAY o

RE: MS 8021.x PEAP failing

2009-08-20 Thread Garber, Neal
> Yup, that line is there. Much of the doc online is WAY out of date, so I'm > wondering if by actually RTFM first I broke something? Ok. This may sound crazy and it may not be your problem, but, I thought I'd mention it anyway.. Look at the samAccountName attribute in A/D for a user that is

RE: MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
OK, got manual PEAP auth working again. -Original Message- From: Gary Gatten Sent: Thursday, August 20, 2009 3:55 PM To: 'FreeRadius users mailing list' Subject: RE: MS 8021.x PEAP failing Whoops! I tried the change you mentioned and now can't get manual auth to

RE: MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
users-bounces+ggatten=waddell@lists.freeradius.or g] On Behalf Of Gary Gatten Sent: Thursday, August 20, 2009 3:22 PM To: FreeRadius users mailing list Subject: RE: MS 8021.x PEAP failing Nope - no love! I'll capture a successful PEAP login when I manually enter the credentials, and

RE: MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
reeradius-users-bounces+ggatten=waddell@lists.freeradius.or g] On Behalf Of Alan Buxey Sent: Thursday, August 20, 2009 2:14 PM To: FreeRadius users mailing list Subject: Re: MS 8021.x PEAP failing Hi, > If in my PEAP conf I uncheck "Automatically use my Windows logon name > and passw

Re: MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
Aug 20 14:09:31 2009 Subject: RE: MS 8021.x PEAP failing > I've been playing around with conf/module files trying to strip the > DOMAIN out of my login request - but no luck! Have you tried "with_ntdomain_hack = yes" in the mschap module config? - List info/subscribe/unsubs

Re: MS 8021.x PEAP failing

2009-08-20 Thread Alan Buxey
Hi, > If in my PEAP conf I uncheck "Automatically use my Windows logon name > and password" and enter my username/password manually - I auth fine. > > I've been playing around with conf/module files trying to strip the > DOMAIN out of my login request - but no luck! this pretty muhc works out of

RE: MS 8021.x PEAP failing

2009-08-20 Thread Garber, Neal
> I've been playing around with conf/module files trying to strip the > DOMAIN out of my login request - but no luck! Have you tried "with_ntdomain_hack = yes" in the mschap module config? - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

MS 8021.x PEAP failing

2009-08-20 Thread Gary Gatten
Hello, I'm relatively new to FR, unlang, etc. - so bear with me. Trying to use M$ XP 802.1x supplicant to auth to a Cisco switch. I've gotten MD5 to work no prob (also vty login to the switch itself using NTLM-Auth) - but can't seem to get EAP-TLS (certs) or PEAP to work. Given that in my cert c