(RADIATOR) EAP and LDAP

Hugh Irvine hugh at open.com.au
Thu Jun 9 02:49:33 CDT 2005


Hello Chris -

I will need to see a copy of the configuration file and a trace 4  
debug showing what is happening in both cases.

regards

Hugh


On 9 Jun 2005, at 17:41, Chris Hills wrote:

> Hugh Irvine wrote:
>
>
>>
>> Hello Chris -
>>
>> As mentioned previously you cannot do a RewriteUsername with  
>> MSCHAP- V2, as the full username including realm is used in the  
>> authentication.
>>
>> regards
>>
>> Hugh
>>
>>
>>
> Hugh
>
> Silly me, yes you did say that. I have dropped the rewrite rule and  
> swapped uid for mailAddress.
>
> Unfortunately I have still had no success (using either SecureW2 or  
> the built in XPSP2 client). It appears though Radiator sends an  
> Access-Challenge packet, but gets nothing in return. The supplicant  
> immediately indicates that authentication failed.
>
> When I configure the supplicant to use EAP-PEAP-TLS, Radiator  
> correctly proxies the request to an IAS server and it successfully  
> authenticates, which leads me to believe the problem is not with  
> the supplicant or the nas.
>
> Regards
>
> -- 
> Chris Hills
> IT Services
> North East Worcestershire College
>


NB:

Have you read the reference manual ("doc/ref.html")?
Have you searched the mailing list archive (www.open.com.au/archives/ 
radiator)?
Have you had a quick look on Google (www.google.com)?
Have you included a copy of your configuration file (no secrets),
together with a trace 4 debug showing what is happening?

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows, MacOS X.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
-
CATool: Private Certificate Authority for Unix and Unix-like systems.


--
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.


More information about the radiator mailing list