freeradius3 unable authenticate ldap user through mschap

Karunagaran D karunad at ssn.edu.in
Thu Nov 7 05:29:40 CET 2019


Dear Sir,
  Thank you for the valuable information, We are using Active Directory. We
will look into the document.

Regards,
Karunad

On Wed, Nov 6, 2019 at 2:13 PM Fajar A. Nugraha <list at fajar.net> wrote:

> On Wed, Nov 6, 2019 at 10:16 AM Karunagaran D <karunad at ssn.edu.in> wrote:
> >
> > Dear Team,
> >
> >    I have configured ldap module and successfully authenticate  in
> radtest,
> > but i Unable to authenticate ldap users through mschap
> >
> > Herewith I am attaching the successful ldap authentication file and
> > unsucessful authentication ldap users through mschap
> >
> >
> > Please help
>
>
> Your log says
>
> (1) mschap: WARNING: No Cleartext-Password configured.  Cannot create
> NT-Password
> (1) mschap: WARNING: No Cleartext-Password configured.  Cannot create
> LM-Password
> (1) mschap: Client is using MS-CHAPv1 with NT-Password
> (1) mschap: ERROR: FAILED: No NT/LM-Password.  Cannot perform
> authentication
>
>
> Meaning your LDAP server doesn't provide Cleartext-Password,
> NT-Password, or LM-password to freeradius.
> If you use Active Directory, you can configure ntlm_auth. But if it's
> something else, and you don't store user passwords as clear text/NT
> hash in ldap, then mschapv2 with ldap won't work. See
> http://deployingradius.com/documents/protocols/oracles.html
>
> --
> Fajar
> -
> List info/subscribe/unsubscribe? See
> http://www.freeradius.org/list/users.html



-- 




D.Karunagaran
Network Administrator,
SSN College of Engineering,
Old Mahabalipuram Road, Kalavakkam -603110, Chennai, India,
Ph: +91-44-27469700/27469772   Ext: 222;

-- 
::DISCLAIMER::


---------------------------------------------------------------------
The 
contents of this e-mail and any attachment(s) are confidential and
intended 
for the named recipient(s) only. Views or opinions, if any,
presented in 
this email are solely those of the author and may not
necessarily reflect 
the views or opinions of SSN Institutions (SSN) or its
affiliates. Any form 
of reproduction, dissemination, copying, disclosure,
modification, 
distribution and / or publication of this message without the
prior written 
consent of authorized representative of SSN is strictly
prohibited. If you 
have received this email in error please delete it and
notify the sender 
immediately.

---------------------------------------------------------------------

Header of this mail should have a valid DKIM signature for the domain 
ssn.edu.in <http://www.ssn.edu.in/>


More information about the Freeradius-Users mailing list