MSCHAPv2 Module with Stripped-Username - no ActiveDirectory

Markus Maurer lists at v-net.tk
Mon Nov 12 12:03:12 CET 2018


Yes, that’s exactly what I need, doing a cleartext auth with rlm_perl with username and otp (in this case I‘m using the users file, for testing purpose) and when this succeeds exec the eap module. The debug log shows that there‘s a challenge for Johndoe:123456 but it uses the external ntlm_auth with the stripped-username (johndoe). 

> Am 12.11.2018 um 11:44 schrieb Adam Bishop <Adam.Bishop at jisc.ac.uk>:
> 
>> On 12 Nov 2018, at 10:43, Adam Bishop <adam.bishop at jisc.ac.uk> wrote:
>> Did you send the right debug log? That shows a user being authenticated from a cleartext password in the users file and the stripped-user-name not being discarded:
> 
> s/not being/being/
> 
> Adam Bishop
> 
>  gpg: E75B 1F92 6407 DFDF 9F1C  BF10 C993 2504 6609 D460
> 
> jisc.ac.uk
> 
> Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.
> 
> Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 2881024, VAT number GB 197 0632 86. The registered office is: One Castle Park, Tower Hill, Bristol BS2 0JA. T 0203 697 5800.  
> 
> 
> -
> List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html



More information about the Freeradius-Users mailing list