Authentication with Kerberos

Josh Howlett josh.howlett at bristol.ac.uk
Thu Jun 15 12:50:04 CEST 2006


thomas hahusseau wrote:
> Hello,
> 
> I would like to set up that kind of configuration :
> 
> EAP-PEAP(Mschapv2) Request ---> AP ---> Freeradius ----> Kerberos 
> authentication to an Active Directory

This isn't possible - EAP-PEAP requires access to the plaintext password 
or NTLM hash.

You should be able to do this with EAP-TTLS, however.

best regards, josh.

> In fact i would like to use Kerberos (wich is supported by Active 
> Directory) instead of ntlm_auth, in freeradius features list avalaible 
> onf the official website I have found :
> 
>     * authentication to a Windows Domain Controller (via ntlm_auth and
>       winbindd)
> 
>     * Kerberos authentication
> 
> Anyone can confirm this possibility to use Kerberos auth with freeradius 
> and maybe any how-to or advices ?
> 
> thank you
> Thomas Hahusseau
> 
> 
> 
> 
> ------------------------------------------------------------------------
> 
> - 
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html




More information about the Freeradius-Users mailing list