Re: PAP/SSHA plus MS-CHAP on 2.17

2010-01-14 Thread Eric Swanson
On Thu, Jan 14, 2010 at 1:29 AM, Alan DeKok wrote: >    *something* is either adding a crypt'd password, or is > forcing the PAP module to use the crypt'd password. > >  Maybe the "unix" module? Good guess! I disabled the "unix" module from authentication and authorization, and everything looks

Re: PAP/SSHA plus MS-CHAP on 2.17

2010-01-14 Thread Alan DeKok
Eric Swanson wrote: > My intent is to use the SSHA password -- of the ones my LDAP system > must maintain, I assumed it would be the most straightforward (better > than those Windows ones anyway). *something* is either adding a crypt'd password, or is forcing the PAP module to use the crypt'd

Re: PAP/SSHA plus MS-CHAP on 2.17

2010-01-14 Thread Eric Swanson
On Thu, Jan 14, 2010 at 12:18 AM, Eric Swanson wrote: > There's not much to the rest of my PAP-related configuration. ...and just for the record, I've just grepped through my whole /etc/raddb folder. The only other non-commented mentions of PAP are in eap.conf, sites-available/inner-tunnel, and

Re: PAP/SSHA plus MS-CHAP on 2.17

2010-01-14 Thread Eric Swanson
On Wed, Jan 13, 2010 at 10:48 PM, Alan DeKok wrote: > Eric Swanson wrote: >> ... >> [ldap] Added User-Password = {SSHA}i9--censored--JI in check items >> [ldap] looking for check items in directory... >> rlm_ldap: sambaNtPassword -> NT-Password == 0x4338--censored--4531 >> rlm_ldap: sambaLmPasswor

Re: PAP/SSHA plus MS-CHAP on 2.17

2010-01-13 Thread Alan DeKok
Eric Swanson wrote: > ... > [ldap] Added User-Password = {SSHA}i9--censored--JI in check items > [ldap] looking for check items in directory... > rlm_ldap: sambaNtPassword -> NT-Password == 0x4338--censored--4531 > rlm_ldap: sambaLmPassword -> LM-Password == 0x4637--censored--4545 You have 3 ver

PAP/SSHA plus MS-CHAP on 2.17

2010-01-13 Thread Eric Swanson
Y'all: Maybe this question obvious for somebody, but I haven't been able to find an answer so far.  I'd appreciate any help on this. I'm setting up freeradius 2.17 with OpenLDAP on CentOS 5.3 (using the pre-built RPM repository from http://people.redhat.com/jdennis/freeradius-rhel-centos).  The s