Wired 802.1X + FreeRADIUS + LDAP issue

Fajar A. Nugraha list at fajar.net
Tue Dec 13 05:43:25 CET 2011


On Tue, Dec 13, 2011 at 11:34 AM, Ryan Garland <sheffy at gmail.com> wrote:
> However, my original problem persists.  My supplicant continues not to
> respond to the FreeRADIUS Access-Challenge.
>
> Keep in mind I am using the same .mobileconfig on my OS X Lion machine
> and my iPhone 4S (IOS 5) and TTLS+PAP works fine for Wireless.  I am
> not sure how to tell which authentication method the supplicant is
> using for Wired as I can only see authentication protocols listed
> under the Wi-Fi section of the profile generated using the iPhone
> Configuration Utility (I was led to believe that the same profile can
> work with both Wired and Wireless 802.1X, hence me being stumped).

Try using something that you know you can configure to use TTLS-PAP.
Like Ubuntu. Just to be extra sure. Even using live CD should be
enough.

>
> If there is not an issue with FreeRADIUS as far as the experts on this
> list can tell from the debug output in my original post (the Wired
> failure attachment),

Pretty much so. You don't have cleartext password in your LDAP schema,
so EAP-MD5 (as well as EAP-PEAP-MSCHAPv2) won't work.

> then I may have to look elsewhere for input
> (Apple support forums perhaps?  Ugh :P)

If Ubuntu works, then it's 100% Apple issue :)

-- 
Fajar




More information about the Freeradius-Users mailing list