Mac-Based auth and HP chap

Alan DeKok aland at deployingradius.com
Wed Apr 29 18:38:06 CEST 2009


jehan procaccia wrote:
> hello,
> I use FreeRADIUS Version 2.1.3, and I try a basic configuration from my
> HP procurve2650 to do Mac-based radius auth.
> for this I've setup a simple users file
> 
> 005004B7252E    Auth-Type := Local, Cleartext-Password := "005004B7252E"

  Delete the "Auth-Type := Local".  It doesn't do anything useful.

> First ,it isn't clear to me wether to user Cleartext-Password or
> User-Password and == ou := , and "" or no "" around the password ...!? ,
> anyway, with Cleartext-Password it works fine with radtest at least

  The example in the FAQ and in the "users" file do NOT have Auth-Type.
They DO use Cleartext-Password, and they DO use ":=".

  All of the third-party web sites, FAQs, etc. are 2-3 years out of
date, and are wrong.

> [chap] login attempt by "005004B7252E" with CHAP password
> [chap] Cleartext-Password is required for authentication

  That says it doesn't have the Cleartext-Password.

...
> [files] users: Matched entry DEFAULT at line 172

  So... what's at line 172?  Where is the "users" file entry you added?

  The FAQ says to add it at the TOP of the "users" file.  That works
best for testing.

  Alan DeKok.



More information about the Freeradius-Users mailing list