mschap : NT-Password has not been normalized by the 'pap' module.

Mohamed Lrhazi Mohamed.Lrhazi at georgetown.edu
Tue Mar 10 16:23:56 CET 2015


I tried but it still failing to authenticate me... does this really mean my
password is wrong?

(8) ldap : Performing search in 'ou=people,dc=georgetown,dc=edu' with
filter '(uid=ml623)', scope 'sub'
(8) ldap : Waiting for search result...
(8) ldap : User object found at DN
"uid=ml623,ou=People,dc=georgetown,dc=edu"
(8) ldap : Processing user attributes
(8) ldap :      control:Password-With-Header += ''{MD4}6DDDAF...''
rlm_ldap (ldap): Released connection (4)
(8)   [ldap] = ok
(8)    if (&control:Password-With-Header =~ /^.MD4.(.*)$/)
(8)    if (&control:Password-With-Header =~ /^.MD4.(.*)$/)  -> TRUE
(8)   if (&control:Password-With-Header =~ /^.MD4.(.*)$/)  {
(8)    update control {
(8) EXPAND {nt}%{1}
(8)    --> {nt}6DDDAF...
(8)     Password-With-Header := '"{nt}6DDDAF..."'
(8)    } # update control = noop
(8)   } # if (&control:Password-With-Header =~ /^.MD4.(.*)$/)  = noop
(8)    if ((ok || updated) && User-Password)
(8)    if ((ok || updated) && User-Password)  -> FALSE
(8)   [expiration] = noop
(8)   [logintime] = noop
(8) WARNING: pap : Auth-Type already set.  Not setting to PAP
(8)   [pap] = noop
(8)  } #  authorize = updated
(8) Found Auth-Type = EAP
(8) # Executing group from file /etc/freeradius/sites-enabled/inner-tunnel
(8)   authenticate {
(8) eap : Expiring EAP session with state 0xc06f3685c0672c5f
(8) eap : Finished EAP session with state 0xc06f3685c0672c5f
(8) eap : Previous EAP request found for state 0xc06f3685c0672c5f, released
from the list
(8) eap : Peer sent MSCHAPv2 (26)
(8) eap : EAP MSCHAPv2 (26)
(8) eap : Calling eap_mschapv2 to process EAP data
(8) eap_mschapv2 : # Executing group from file
/etc/freeradius/sites-enabled/inner-tunnel
(8) eap_mschapv2 :  Auth-Type MS-CHAP {
(8) WARNING: mschap : No Cleartext-Password configured.  Cannot create
LM-Password
(8) WARNING: mschap : NT-Password has not been normalized by the 'pap'
module.  Authentication will fail
(8) mschap : Creating challenge hash with username: ml623
(8) mschap : Client is using MS-CHAPv2
(8) ERROR: mschap : FAILED: No NT/LM-Password.  Cannot perform
authentication
(8) ERROR: mschap : MS-CHAP2-Response is incorrect
(8)   [mschap] = reject
(8)  } # Auth-Type MS-CHAP = reject
(8) eap : Freeing handler
(8)   [eap] = reject
(8)  } #  authenticate = reject
(8) Failed to authenticate the user.



On Tue, Mar 10, 2015 at 10:57 AM, Alan DeKok <aland at deployingradius.com>
wrote:

> On Mar 10, 2015, at 10:54 AM, Mohamed Lrhazi <
> Mohamed.Lrhazi at georgetown.edu> wrote:
> > What do I need to change this to:
>
>   Nothing.  Try it and see.
>
>   Alan DeKok.
>
>
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html
>


More information about the Freeradius-Users mailing list