freeradius+peap+mschap+AD

Aniss Nazerian aniss.nazerian at vxu.se
Mon Apr 26 14:09:19 CEST 2010


Hi,
I have some strange problems with peap+mschap+AD
I followed the howto on the wiki for AD but with no luck.
When authenticating a user I'll get:
----
Info: ++[mschap] returns ok
Debug: MSCHAP Success
----
So i assume that the auth. against AD is OK

but then the inner tunnel does something....

} # server inner-tunnel
Mon Apr 26 12:32:15 2010 : Info: [peap] Got tunneled reply code 11
        EAP-Message =
0x010700331a0306002e533d35454536463235384339353037434438373938303137334434424545393533373537304537393443
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x55964b77549151644066a939db03f531
Mon Apr 26 12:32:15 2010 : Info: [peap] Got tunneled reply RADIUS code 11
        EAP-Message =
0x010700331a0306002e533d35454536463235384339353037434438373938303137334434424545393533373537304537393443
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x55964b77549151644066a939db03f531
Mon Apr 26 12:32:15 2010 : Info: [peap] Got tunneled Access-Challenge
Mon Apr 26 12:32:15 2010 : Info: ++[eap] returns handled
Sending Access-Challenge of id 0 to 194.47.88.154 port 2051
        EAP-Message =
0x0107005b19001703010050154c3b195ed5a3fa88fd21477529cf86ee7d1d98cf8eb918036ac8aa14cd6f8c66a1836e9ab27087ad7df766d20447dbce1247b6a9ccf6b4376d854978db210db60f9b3578592123a4c5d43a205e8f79
        Message-Authenticator = 0x00000000000000000000000000000000
        State = 0x3b975d133d90441898602b7c0076958a
Mon Apr 26 12:32:15 2010 : Info: Finished request 6.

After that nothing happens.

I'm using:
FreeRADIUS Version 2.1.1
I have tried both OS X 10.6 and Ubuntu 10.04 clients
I have tried changing AP from CISCO to a Linksys WRT-54GL with DD-WRT
with no luck.

Has anyone any idea on whats wrong?

-- 
Aniss Nazerian, IT-Department, Linnaeus University
Phone: +46-470-708183, E-mail:aniss.nazerian at vxu.se

O< ascii ribbon campaign - stop html mail - www.asciiribbon.org



More information about the Freeradius-Users mailing list