ntlm_auth with ms-chap

Alan DeKok aland at deployingradius.com
Sat Sep 1 14:56:02 CEST 2018


On Sep 1, 2018, at 8:17 AM, J├╝rgen Obermeyer <om at oegym.de> wrote:
> 
> Not able to get ntlm_auth working, I switched now to krb5. 'radtest' says:

  That's good, but we don't need to see the output of radtest.

> May I ignore the "PAP WARNINGS"?

  Yes.

> And will wireless clients (or the
> users) authenticate if 'radtest' (via ssh) is successfull?

  Only EAP-TTLS will work.  PEAP will not.  That's because only EAP-TTLS supplies the clear text password that is needed by krb5.

  Something is very wrong with the Samba / AD infrastructure if MS-CHAP doesn't work.

  Alan DeKok.




More information about the Freeradius-Users mailing list