Password oddity

Matthew Stavert Matthew.Stavert at
Thu Dec 16 21:33:19 CET 2010

Hi Gary, I'm from Northern Lights school Division 69, We run Sles 10, with OES2 SP2 services on it, and are using edirectory 8.8 SP5 (I think the newest one), and guess what, I'm using radius 2.1.9, and it works like a hot damn.  I think i can help you :)  I have Freeradius, Authenticating against edir, with about 300+ users.  My authetication uses the secure certificate from the Novell OES2 server embedded into freeradius, and I have no authentication issues (Other than the users choking out the access points with youtube ;)  my config even follows edir policy, IE disables accounts, time frames etc.

Let me know if you're interested in that.


Anyways, I could probably modify my instructions to meet your sites needs.  

Matthew Stavert 
Information Systems Analyst
NLSD. 69

PH:    780-826-3145
Cell:  780-207-1146


>>> Gary Gatten <Ggatten at> 12/15/2010 4:52 PM >>>
Someone will for SURE yell at you for using something that old.  Or, they'll just ignore you.

That is a weird a$$ problem for sure!  Why can't you  upgrade?  At LEAST to the latest 1.x version?

-----Original Message-----
From: at [ at] On Behalf Of discgolfer72
Sent: Wednesday, December 15, 2010 5:36 PM
To: freeradius-users at
Subject: Password oddity

Set up FreeRadius on SLES 10. Using the NTRadPing utility we can authenticate
to our back end LDAP server (eDirectory) w/o problem. However, when we
enabled Radius authentication on two separate Wireless access points
(Linksys WRT54 and DLink WBR 1310), they both fail authentication because
the password they pass (or how FreeRadius interprets the password) changes
one letter of the password.

For example, we set up a radtest user with a password of radtest. FreeRadius
server in debug shows the request come in but passes a password value of
aadtest. So, as a test we changed the password to aadtest for the radtest
user. The password then came across as badtest. So, we thought we'd change
the password to cadtest to see what would happen. Now the password was
sent/received as aadtest again.

Using NTRadPing utility, we see the request come in, get processed and then

Running FreeRadius 1.1.0 as this is the version that Novell "supports." 
Please don't yell at me on this.  Their documentation is based on this
version and not the latest version.......

Has anyone seen this behavior before and if so, know how to fix it?

View this message in context:
Sent from the FreeRadius - User mailing list archive at
List info/subscribe/unsubscribe? See

<font size="1">
<div style='border:none;border-bottom:double windowtext 2.25pt;padding:0in 0in 1.0pt 0in'>
"This email is intended to be reviewed by only the intended recipient
and may contain information that is privileged and/or confidential.
If you are not the intended recipient, you are hereby notified that
any review, use, dissemination, disclosure or copying of this email
and its attachments, if any, is strictly prohibited.  If you have
received this email in error, please immediately notify the sender by
return email and delete this email from your system."

List info/subscribe/unsubscribe? See
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: image/jpg
Size: 16244 bytes
Desc: not available
URL: <>

More information about the Freeradius-Users mailing list