Re: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Artur Hecker
that's getting quite consuming, but who says a must say b, right? :-) Please do not take my e-mails personally... I must say that I thought you might be one of those show offs who pick through peoples e-mails looking for mistakes and then completely mis the point of the e-mail. My appologies if I

RE: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Tom Rixom
Good, I guess it would be a boring world if we never tried to challenge each other... ;) Tom. > -Original Message- > From: Artur Hecker [mailto:[EMAIL PROTECTED] > Sent: Thursday, February 26, 2004 1:15 PM > To: [EMAIL PROTECTED] > Subject: Re: PEAP / MSCHAP2 / LDAP

RE: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Tom Rixom
h that story? Regards, Tom Rixom > -Original Message- > From: Artur Hecker [mailto:[EMAIL PROTECTED] > Sent: Thursday, February 26, 2004 11:30 AM > To: [EMAIL PROTECTED] > Subject: Re: PEAP / MSCHAP2 / LDAP > > > hi > > > > I just can't leav

Re: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Artur Hecker
hi I just can't leave it alone sorry... yes it actually seems to bother you more than i would have expected, but well... :-) You talk about an attacker attacking the NTHASH... Why did you bring this in? I thought the discussion was about PEAP-MSCHAPV2 LDAP compatibility... actually, for

Re: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Artur Hecker
*?* what's the problem, tom? nobody tries to show off. look at the original post. is it correct in your opinion? if not, how does it help? now, talking about the original author, i think that he can say himself if he found my answer to his post arrogant or offensive. i didn't mean to be presu

RE: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Tom Rixom
the line? bye, Tom. > -Original Message- > From: Tom Rixom > Sent: Thursday, February 26, 2004 10:37 AM > To: [EMAIL PROTECTED] > Subject: RE: PEAP / MSCHAP2 / LDAP > > > Are you trying to help or is this just one of those pointless > discussions in > where we show off

RE: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Tom Rixom
4 9:46 AM > To: [EMAIL PROTECTED] > Subject: Re: PEAP / MSCHAP2 / LDAP > > > hi > > > Tom Rixom wrote: > > How do you explain that Microsoft Clients almost all use > MSCHAP in some form > > to authenticate and that all Microsoft passwords are stored > in

Re: PEAP / MSCHAP2 / LDAP

2004-02-26 Thread Artur Hecker
hi Tom Rixom wrote: How do you explain that Microsoft Clients almost all use MSCHAP in some form to authenticate and that all Microsoft passwords are stored in encrypted form... ;) remark: i've never talked about encryption. encryption is always reversible, provided that you have the key. i've a

RE: PEAP / MSCHAP2 / LDAP

2004-02-25 Thread John De Villiers
On Wed, 2004-02-25 at 21:33, Tom Rixom wrote: > How do you explain that Microsoft Clients almost all use MSCHAP in some form > to authenticate and that all Microsoft passwords are stored in encrypted form... ;) > > Did you read the MSCHAPV2 specs before writing the e-mail? > > I can't recall th

RE: PEAP / MSCHAP2 / LDAP

2004-02-25 Thread Tom Rixom
heated oven gasmark 10 and he presto there is your crypto link. Regards, Tom Rixom -Oorspronkelijk bericht- Van: Artur Hecker [mailto:[EMAIL PROTECTED] Verzonden: wo 25-2-2004 19:39 Aan: [EMAIL PROTECTED] CC: Onderwerp: Re: PEAP / MSCHAP2 / LDAP <>

Re: PEAP / MSCHAP2 / LDAP

2004-02-25 Thread Artur Hecker
hi chris the implications you mention might be correct but sorry, i don't think your explanation is correct. the problem is that if the NT-hashes are not reversible (as you claim), than you couldn't have been storing them in your LDAP with whichever protocol (e.g. not with MS-CHAPv2 as you cla

Re: PEAP / MSCHAP2 / LDAP

2004-02-25 Thread Chris Wieringa
>On Wed, 2004-02-25 at 08:30, Arthur EBEL wrote: >> I would like to use PEAP / MSCHAP2 / LDAP >> My password is stored in my LDAP directory using Crypt. >See many many previous discussions in this list on the requirement of >cleartext passwords for MS-CHAP. OK, time for some user education has to

Re: PEAP / MSCHAP2 / LDAP

2004-02-25 Thread Michael Griego
See many many previous discussions in this list on the requirement of cleartext passwords for MS-CHAP. --Mike On Wed, 2004-02-25 at 08:30, Arthur EBEL wrote: > I would like to use PEAP / MSCHAP2 / LDAP > > But I have got this kind of erros and my users cant authenticate > > > rlm_mschap: No U