RE: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-26 Thread Kevin Elliott
- Host Account Authentication Only Hi, Currently FreeRadius will send back Access-Accepts for *both* user and machine/host accounts (in the Active Directory context of those terms). I would like to configure FreeRadius to ignore or reject authentication requests using the user

PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread Kevin Elliott
I have a working setup using FreeRadius 2.1.10 doing PEAP/MSCHAPv2 against a 2008 R2 Domain Controller via Samba 2.3.5.6 all running on Debian 6.0.4. My clients are D-Link DWL3200 and D-Link DAP-2360 access points. I am using the builtin Windows XP SP3 802.1x supplicant. Currently FreeRadius

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread Matthew Newton
On Wed, Apr 25, 2012 at 11:52:15AM -0800, Kevin Elliott wrote: Currently FreeRadius will send back Access-Accepts for *both* user and machine/host accounts (in the Active Directory context of those terms). I would like to configure FreeRadius to ignore or reject authentication requests using

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread alan buxey
Hi, Currently FreeRadius will send back Access-Accepts for *both* user and machine/host accounts (in the Active Directory context of those terms). I would like to configure FreeRadius to ignore or reject authentication requests using the user creditionals. I spent the better part of

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread alan buxey
hi, Matthew, I would say the check is a little sparseand assumes nothing else is in play...such as realms/proxying for what if my username was host\u...@other.realm.com its quite likely that this user would get proxied back to their home site.hence better to ensure the regex pattern

Re: PEAP/MSCHAPv2 - Host Account Authentication Only

2012-04-25 Thread Matthew Newton
Hi On Wed, Apr 25, 2012 at 11:58:06PM +0100, alan buxey wrote: Matthew, I would say the check is a little sparseand assumes Yeah, good idea checking the RHS of the username - hadn't thought of that (scuttles off to implement it :) ) oh. actually, yes, you should ignore that i said add it