freeradius3 unable authenticate ldap user through mschap

Karunagaran D karunad at
Thu Nov 7 05:29:40 CET 2019

Dear Sir,
  Thank you for the valuable information, We are using Active Directory. We
will look into the document.


On Wed, Nov 6, 2019 at 2:13 PM Fajar A. Nugraha <list at> wrote:

> On Wed, Nov 6, 2019 at 10:16 AM Karunagaran D <karunad at> wrote:
> >
> > Dear Team,
> >
> >    I have configured ldap module and successfully authenticate  in
> radtest,
> > but i Unable to authenticate ldap users through mschap
> >
> > Herewith I am attaching the successful ldap authentication file and
> > unsucessful authentication ldap users through mschap
> >
> >
> > Please help
> Your log says
> (1) mschap: WARNING: No Cleartext-Password configured.  Cannot create
> NT-Password
> (1) mschap: WARNING: No Cleartext-Password configured.  Cannot create
> LM-Password
> (1) mschap: Client is using MS-CHAPv1 with NT-Password
> (1) mschap: ERROR: FAILED: No NT/LM-Password.  Cannot perform
> authentication
> Meaning your LDAP server doesn't provide Cleartext-Password,
> NT-Password, or LM-password to freeradius.
> If you use Active Directory, you can configure ntlm_auth. But if it's
> something else, and you don't store user passwords as clear text/NT
> hash in ldap, then mschapv2 with ldap won't work. See
> --
> Fajar
> -
> List info/subscribe/unsubscribe? See


Network Administrator,
SSN College of Engineering,
Old Mahabalipuram Road, Kalavakkam -603110, Chennai, India,
Ph: +91-44-27469700/27469772   Ext: 222;


contents of this e-mail and any attachment(s) are confidential and
for the named recipient(s) only. Views or opinions, if any,
presented in 
this email are solely those of the author and may not
necessarily reflect 
the views or opinions of SSN Institutions (SSN) or its
affiliates. Any form 
of reproduction, dissemination, copying, disclosure,
distribution and / or publication of this message without the
prior written 
consent of authorized representative of SSN is strictly
prohibited. If you 
have received this email in error please delete it and
notify the sender 


Header of this mail should have a valid DKIM signature for the domain <>

More information about the Freeradius-Users mailing list