mschap via ntlm_auth over a socket

Matthew Newton mcn4 at leicester.ac.uk
Fri Dec 5 01:22:00 CET 2014


On Wed, Dec 03, 2014 at 10:59:55AM -0500, Arran Cudbard-Bell wrote:
> 
> > On 3 Dec 2014, at 06:05, Matthew Newton <mcn4 at LEICESTER.AC.UK> wrote:
> > 
> > On Tue, Dec 02, 2014 at 08:28:07PM -0500, Arran Cudbard-Bell wrote:
> >>> On 2 Dec 2014, at 19:33, Matthew Newton <mcn4 at LEICESTER.AC.UK> wrote:
> >>> I've just done a pull request, but I'm sure there are things that
> >>> need looking at or fixing even if the idea possibly sane. Let me
> >>> know.
> >> 
> >> Very nice! Possible improvement (and I may be completely wrong here)
> >> but shouldn't it be possible to fork/exec and create a pipe with the 
> >> ends mapped to stdin/stdout of the execed process?
> >> 
> >> Slightly less configuration, and maybe slight performance improvement.

OK, that was simpler than I thought.

I've also updated a few other bits and pushed to github.

  https://github.com/FreeRADIUS/freeradius-server/pull/848

Testing looks similar (though times are less; possibly due to
compiling without enable-developer, or pulseaudio not eating vast
amounts of CPU). 1000 iterations of eapol_test on a single box
with Samba backend.

 internal 15.9s
 ntlm_auth 23.9s
 ntlm_auth_helper 17.0s

Cheers,

Matthew


-- 
Matthew Newton, Ph.D. <mcn4 at le.ac.uk>

Systems Specialist, Infrastructure Services,
I.T. Services, University of Leicester, Leicester LE1 7RH, United Kingdom

For IT help contact helpdesk extn. 2253, <ithelp at le.ac.uk>


More information about the Freeradius-Devel mailing list