Wireless WPA2 enterprise Radius authentication

Sven Hartge sven at svenhartge.de
Wed Oct 27 21:47:02 CEST 2010


Maurice James <midnightsteel at msn.com> wrote:

> [ldap] looking for check items in directory...
>  [ldap] userpassword -> User-Password == "{SSHA}5wzxRoUPX/rLkS9hY1HztczPN8u5m/dGDzKvdg=="

This will not work. You need a cleartext password. This SSHA-Hash is
only good for PAP, any challenge response method like MSCHAPv2 won't
function with this.

> [mschap] No Cleartext-Password configured.  Cannot create LM-Password.
> [mschap] No Cleartext-Password configured.  Cannot create NT-Password.
> [mschap] Told to do MS-CHAPv2 for MJames with NT-Password
> [mschap] FAILED: No NT/LM-Password.  Cannot perform authentication.
> [mschap] FAILED: MS-CHAP2-Response is incorrect
> ++[mschap] returns reject

And this is the result --> reject.

Grüße,
Sven.

-- 
Sig lost. Core dumped.




More information about the Freeradius-Users mailing list