RE: FR and PEAP question

2008-06-11 Thread Ivan Kalik
>In ldap.attrmap I have the line: >checkItem NT-Password ntPassword > >in radiusd.conf in my ldap declaration, I have: >password_attribute = ntPassword > And that would work if you were using pap module. But you are using mschap. That one looks for cleartext password first. If

Re: FR and PEAP question

2008-06-11 Thread Nicolas Goutte
Thanks [...] Matt [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ivan Kalik Sent: Tuesday, June 10, 2008 11:21 AM To: freeradius-users@lists.freeradius.org Subject: RE: FR and PEAP question eapol_test from wpa_supplicant JRad

RE: FR and PEAP question

2008-06-11 Thread Matt Ashfield
Wed Jun 11 09:42:08 2008 : Debug: Cleaning up request 1 ID 3 with timestamp +355 Wed Jun 11 09:42:08 2008 : Debug: Ready to process requests. Matt [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ivan Kalik Sent: Tuesday, June 10

RE: FR and PEAP question

2008-06-10 Thread Ivan Kalik
here. > >Matt >[EMAIL PROTECTED] > > >-Original Message- >From: [EMAIL PROTECTED] >[mailto:[EMAIL PROTECTED] On Behalf >Of Ivan Kalik >Sent: Tuesday, June 10, 2008 11:02 AM >To: freeradius-users@lists.freeradius.org >Subject: RE: FR and PEAP question > &g

Re: FR and PEAP question

2008-06-10 Thread Alan DeKok
Matt Ashfield wrote: > I'd like to test this with PEAP/MSCHAP requests if possible. Is there a > howto? Clearly I'm down the wrong path here. I'm in the process of writing some howto's for my deployingradius.com web page. But $$ work comes first. In short: - start with default config (as al

RE: FR and PEAP question

2008-06-10 Thread Matt Ashfield
freeradius-users@lists.freeradius.org Subject: RE: FR and PEAP question FreeRADIUS-Proxied-To == 127.0.0.1 will match only for eap requests. You can't test for it with pap requests (radtest). Ivan Kalik Kalik Informatika ISP Dana 10/6/2008, "Matt Ashfield" <[EMAIL PROTECTED]>

RE: FR and PEAP question

2008-06-10 Thread Ivan Kalik
groups I have this. Although I am unsure if this is correct. >UNBFWSS NAS-IP-Address == 127.0.0.1 > > >Matt >[EMAIL PROTECTED] > > >-Original Message- >From: [EMAIL PROTECTED] >[mailto:[EMAIL PROTECTED] On Behalf >Of Ivan Kalik >Sent: Tuesday, June

RE: FR and PEAP question

2008-06-10 Thread Matt Ashfield
: freeradius-users@lists.freeradius.org Subject: RE: FR and PEAP question >The password that is being supplied by radtest is in plain-text, should I be >supplying it in ntPassword-encrypted format? No. > >It looks to me like I have something wrong with my authenticate section. > >My

RE: FR and PEAP question

2008-06-10 Thread Ivan Kalik
>The password that is being supplied by radtest is in plain-text, should I be >supplying it in ntPassword-encrypted format? No. > >It looks to me like I have something wrong with my authenticate section. > >My authorize section looks like: >authorize { >preprocess >chap >m

RE: FR and PEAP question

2008-06-10 Thread Matt Ashfield
ny assistance is appreciated. Thanks Matt [EMAIL PROTECTED] -Original Message- From: Thibault Le Meur [mailto:[EMAIL PROTECTED] Sent: Monday, May 26, 2008 11:00 AM To: [EMAIL PROTECTED]; FreeRadius users mailing list Subject: Re: FR and PEAP question Matt Ashfield a écrit : > > Hi,