Limitation of authenticating against AD

Alan DeKok aland at deployingradius.com
Wed Sep 3 18:01:53 CEST 2014


Dennis Xu wrote:
> I am looking for confirmation that because our AD stores passwords in crypt'd or SHA1 format, we cannot use FreeRadius to authenticate against our AD using PEAP and EAP-MSCHAPv2?

  No.  AD stores it's passwords in NT-Hash format.  And it does NOT
allow FreeRADIUS (or anyone) to read those passwords via LDAP.

> http://deployingradius.com/documents/protocols/compatibility.html
> 
> Is the above link still up-to-date? 

  Yes.

  Alan DeKok.


More information about the Freeradius-Users mailing list