Freeradius PEAP/MSCHAPv2 against Apple OpenDirectory

John elmer_radius at
Fri Mar 19 04:04:47 CET 2010

I attached the captured packets. Please open it with wireshark. 
The password from OD is “********”.  It is neither cleartext password nor encrypted password.

--- 10年3月18日,周四, John <elmer_radius at> 写道:

发件人: John <elmer_radius at>
主题: Re: Freeradius PEAP/MSCHAPv2 against Apple OpenDirectory
收件人: "FreeRadius users mailing list" <freeradius-users at>
日期: 2010年3月18日,周四,下午7:01

I configured the LDAP module talks to Open Directory, based on the debug looks the password fetched from OD, but the authentication always failed. Is there any guide for freeRADIUS+ldap+OD integrating?
I setup freeRADIUS talks to OpenLDAP, it works well.  Can OD return cleartext password like OpenLDAP do?


--- 10年3月15日,周一, Alan DeKok <aland at> 写道:

发件人: Alan DeKok <aland at>
主题: Re: Freeradius PEAP/MSCHAPv2 against Apple OpenDirectory
收件人: "FreeRadius users mailing list" <freeradius-users at>
日期: 2010年3月15日,周一,下午12:59

John wrote:
> Hello,
> We want to setup freeRADIUS with Peap/MSCHAPv2 talk to Apple Open
> Directory. I found this option 'use_open_directory'. But looks we need
> to install freeRADIUS on the same machine with Open
> Directory.(
> Do we have to run freeRADIUS on the same machine with OpenDirectory?


> Is
> there a work-around that we can run freeRADIUS seperate from OpenDirectory?

  OpenDirectory is an LDAP server.  Configure that way in FreeRADIUS.
It might work.

  Alan DeKok.
List info/subscribe/unsubscribe? See


List info/subscribe/unsubscribe? See

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: ODldap.pcap
Type: application/octet-stream
Size: 932 bytes
Desc: not available
URL: <>

More information about the Freeradius-Users mailing list