FreeRADIUS + OpenLDAP + MSCHAPv2
Tim Gustafson
tjg at soe.ucsc.edu
Tue Nov 18 22:29:48 CET 2008
Ok, I've upgraded to FreeRADIUS 2.0.5 on a FreeBSD box (the FreeBSD ports is more up-to-date than the CentOS Yum repositories apparently).
However, upon reading the documentation in modules/ldap, I see this:
# However, LDAP can be used for authentication ONLY when the
# Access-Request packet contains a clear-text User-Password
# attribute. LDAP authentication will NOT work for any other
# authentication method.
#
# This means that LDAP servers don't understand EAP. If you
# force "Auth-Type = LDAP", and then send the server a
# request containing EAP authentication, then authentication
# WILL NOT WORK.
So, does this mean that you can't do MSCHAPv2 against an LDAP server, or am I missing something again?
Tim Gustafson
SOE Webmaster
UC Santa Cruz
tjg at soe.ucsc.edu
831-459-5354
More information about the Freeradius-Users
mailing list