Re: login_radius support for encrypted authentication type?

2012-12-17 Thread Stuart Henderson
On 2012-12-13, Aleš Golob wrote: > Hi! > > I have an OpenBSD 5.2 installation on a Soekris net4801 used as > a router, DNS server and a SSH tunnel proxy. > > I have configured the login_radius service in my login.conf and > all works reasonably well but from what I can tell login_radius > only sup

Re: login_radius support for encrypted authentication type?

2012-12-17 Thread Aleš Golob
o the point of code audits and yet it supports only PAP. Aleš Golob > -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On > Behalf Of Stephen Spencer > Sent: Thursday, December 13, 2012 3:32 PM > To: misc@openbsd.org > Subject: Re: l

Re: login_radius support for encrypted authentication type?

2012-12-13 Thread Stephen Spencer
I haven't worked with OpenBSD in this context, but I've setup 802.1X auth for layer-2 wireless. It's LDAP backed. We happen to also run a samba3 domain, so LDAP also stores NTLM hashes. I'm not a radius expert, but the only mechanism that seems to be able to deal with non clear passwords see

login_radius support for encrypted authentication type?

2012-12-13 Thread Aleš Golob
Hi! I have an OpenBSD 5.2 installation on a Soekris net4801 used as a router, DNS server and a SSH tunnel proxy. I have configured the login_radius service in my login.conf and all works reasonably well but from what I can tell login_radius only supports the clear-text PAP authentication type.