Re: working with vouchers

2012-07-10 Thread Phil Mayers
On 07/09/2012 06:30 PM, Andreas Meyer wrote: Ok, thank you for the hints! Everything is getting clearer by and by. I just found out that I get entry into the WLAN with an android smartphone by just using the username and password without using the ca.crt with PEAP/MSchap2. I read in the

Re: working with vouchers

2012-07-09 Thread Andreas Meyer
Fajar A. Nugraha l...@fajar.net wrote: On Thu, Jul 5, 2012 at 11:05 PM, Andreas Meyer anme...@anup.de wrote: Is there a big picture somewhere available for the freeradius-server like it is for postfix for example? I want to understand the contiguities between proxiing, outer-tunnel,

Re: working with vouchers

2012-07-09 Thread Alan Buxey
Yrs, if you don't care about security and verification of server cert, then just username and password will work with PEAP. Some clients will throw up warning messages (that users ignore)..messages can be reduced by using a CA that is known by the clients. The above is not best practice under

Re: working with vouchers

2012-07-09 Thread Andreas Meyer
Alan Buxey a.l.m.bu...@lboro.ac.uk wrote: Yrs, if you don't care about security and verification of server cert, then just username and password will work with PEAP. Some clients will throw up warning messages (that users ignore)..messages can be reduced by using a CA that is known by the

Re: working with vouchers

2012-07-09 Thread alan buxey
Hi, Oh yes, I just read the wikipedia about all that stuff about chap and pap and PEAP and MS-chapv2 and EAP and TLS and so on. This is heavy rock. its proper protection of credentials ..and proper trust/verification that you are sending your details to the right place (well, with

Re: working with vouchers

2012-07-05 Thread Andreas Meyer
Hi! alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, Hello! Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate to the radiusserver over the authenticator?

Re: working with vouchers

2012-07-05 Thread Fajar A. Nugraha
On Thu, Jul 5, 2012 at 3:43 PM, Andreas Meyer anme...@anup.de wrote: Hi! alan buxey a.l.m.bu...@lboro.ac.uk wrote: Hi, Hello! Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this

Re: working with vouchers

2012-07-05 Thread Andreas Meyer
Fajar A. Nugraha l...@fajar.net wrote: On Thu, Jul 5, 2012 at 3:43 PM, Andreas Meyer anme...@anup.de wrote: Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate

Re: working with vouchers

2012-07-05 Thread Fajar A. Nugraha
On Thu, Jul 5, 2012 at 11:05 PM, Andreas Meyer anme...@anup.de wrote: Is there a big picture somewhere available for the freeradius-server like it is for postfix for example? I want to understand the contiguities between proxiing, outer-tunnel, inner-tunnel for example. That's a different

working with vouchers

2012-07-04 Thread anmeyer
Hello! Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate to the radiusserver over the authenticator? Please be patient with me! Andreas - List

Re: working with vouchers

2012-07-04 Thread alan buxey
Hi, Hello! Without considering any security is it possible to hand out a voucher to a client with just the ESSID, the username and the password written down and this client can authenticate to the radiusserver over the authenticator? Please be patient with me! depends on the methods used,