PEAP/MSCHAPv2 bounded to a particular MAC Address

Marco Gaiarin gaio at sv.lnf.it
Thu Jan 30 10:54:10 CET 2014


Mandi! Alan DeKok
  In chel di` si favelave...

> > [ Sorry, i'm not subscribed to that list, i will follow it on the web
> >   interface but if you can, put me on CC. Thanks. ]
>   You should make it easy for people to help you.  If you make it hard,
> you will probably be ignored.

I think it was not a so big trouble. I've re-enabled email receiving in
mailman. sorry.


> > 	username1      User-Password := "password1", MS-CHAP-Use-NTLM-Auth := 0, Expiration := "Apr 29 2010 18:00:00"
>   Well, that's wrong.

...but it works. ;-)


>  We've been recommending Cleartext-Password
> instead of User-Password in for almost 10 years now.

Probably my freeradius setup was built exactly 10 years ago. I was not
aware of that, or i've missed that. Sorry.
I will change my config files and upgrade my internal wiki. Thanks.


>   See the FAQ for "it doesn't work".

If you meant:
	http://wiki.freeradius.org/guide/FAQ

i've read the faq, but i've not found anything that i think is related
to my trouble.
As i've just stated, i've also found:
	http://wiki.freeradius.org/guide/Mac%20Auth
but also on that i've not found information (apart calling-station-id
normaization, that i've to implement surely...) that seems to me
useful/related.

Probably i'm not a so bright sysadmin, probably freeradius (generally:
RADIUS) is not a so simple service to setup, but on the past i've go
through the docs/wiki/... and fix some little trouble (the last, username
normalization, because win7 client send username/hostname in CAPITAL
letters, and winxp not), but really i've no clue on how to handle that
task.


So:

>   There's a reason it's in the FAQ (and README, "man" page, and daily on
> this list).
>   If you're not going to bother following the documentation, then it's
> no surprise you can't get it to work.

i'm very happy to know that there's a reason because does not work (and
so, i suppose a solution to make it work) but really i'm now able to
even see them on «the FAQ (and README, "man" page, and daily on this
list)». Sorry.

Can you (or, some other list member) provide me at least some hint? I'm
only asking that.


Thanks to all.

-- 
dott. Marco Gaiarin				        GNUPG Key ID: 240A3D66
  Associazione ``La Nostra Famiglia''                    http://www.sv.lnf.it/
  Polo FVG   -   Via della Bontà, 7 - 33078   -   San Vito al Tagliamento (PN)
  marco.gaiarin(at)lanostrafamiglia.it   t +39-0434-842711   f +39-0434-842797

		Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA!
	   http://www.lanostrafamiglia.it/chi_siamo/5xmille.php
	(cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)


More information about the Freeradius-Users mailing list