(RADIATOR) EAP and LDAP

Chris Hills chills at ne-worcs.ac.uk
Thu Jun 9 02:41:06 CDT 2005


Hugh Irvine wrote:

>
> Hello Chris -
>
> As mentioned previously you cannot do a RewriteUsername with MSCHAP- 
> V2, as the full username including realm is used in the authentication.
>
> regards
>
> Hugh
>
>
Hugh

Silly me, yes you did say that. I have dropped the rewrite rule and 
swapped uid for mailAddress.

Unfortunately I have still had no success (using either SecureW2 or the 
built in XPSP2 client). It appears though Radiator sends an 
Access-Challenge packet, but gets nothing in return. The supplicant 
immediately indicates that authentication failed.

When I configure the supplicant to use EAP-PEAP-TLS, Radiator correctly 
proxies the request to an IAS server and it successfully authenticates, 
which leads me to believe the problem is not with the supplicant or the nas.

Regards

-- 
Chris Hills
IT Services
North East Worcestershire College

--
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.


More information about the radiator mailing list