Freeraius vs NPS

Martin, Jeremy jmartin at emcc.edu
Fri May 5 05:48:18 CEST 2017


I would like to thank everyone for there time, looks like we are going to have to stick with NPS as it seem to be the product that supports the solution that returns whatever needs to be returned back to the switch.  In this particular case though nothing to do with MS-CHAP its all MD5 based.

Jeremy


> On May 4, 2017, at 10:09 PM, Alan DeKok <aland at deployingradius.com> wrote:
> 
> 
>> On May 4, 2017, at 9:21 PM, Martin, Jeremy <jmartin at emcc.edu> wrote:
>> 
>> I partly agree, I agree that there are things going on but the part that points to the server having something to do with it is the fact that everything left the save, phone, switches, switch configuration yields a different result only when the radius server is changed so this leads me to believe there must be a difference in some value passed,
> 
>  As I said... there are a *lot* of things going on with EAP.  It's not as simple as "some value".  It's a whole set of protocol suites, and a whole set of negotiation.
> 
>  The short answer is that the end system *should* prompt for credentials on first login.
> 
>  After that, you'll probably need to configure MS-CHAP change password.  Which means upgrading to 3.0.13.  The functionality is documented in raddb/mods-available/mschap.
> 
>  Alan DeKok.
> 
> 
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html




More information about the Freeradius-Users mailing list