(RADIATOR) PEAP issue

Hugh Irvine hugh at open.com.au
Wed Feb 27 01:08:25 CST 2008


Salut Pascal -

You should be using Radiator 4.1 which was released late last week,  
as there are some important fixes and patches.

And on Windows I suggest you use the AuthBy LSA clause rather than  
the AuthBy LDAP2 clause.

See the example in "goodies/lsa_eap_peap.cfg".

hope that helps

regards

Hugh


On 27 Feb 2008, at 07:27, Pascal Beauregard wrote:

> Hi,
> we are evaluating Radiator 4.0 on a Windows 2003 R2 server. We are  
> trying to get PEAP to work  and we can't figure out what is not  
> working.
>
> I have attached the logfile and the configuration files.
>
> Here is a sample of the log file that contains the error message
>
> Tue Feb 26 10:23:14 2008: DEBUG: Radius::AuthLDAP2 looks for match  
> with beap1910 [anonymous]
> Tue Feb 26 10:23:14 2008: DEBUG: Radius::AuthLDAP2 ACCEPT: :  
> beap1910 [anonymous]
> Tue Feb 26 10:23:14 2008: DEBUG: EAP result: 1, EAP MSCHAP-V2  
> Authentication failure
> Tue Feb 26 10:23:14 2008: DEBUG: AuthBy LDAP2 result: REJECT, EAP  
> MSCHAP-V2 Authentication failure
> Tue Feb 26 10:23:14 2008: INFO: Access rejected for anonymous: EAP  
> MSCHAP-V2 Authentication failure
>
> I found strange that the AuthLDAP2 is accepted but the EAP result  
> is a failure.
>
>
>  Thanks!
>
> Pascal Beauregard
>
> Analyste en télécommunications
> Université de Sherbrooke
> (819)821-7770
> www.usherbrooke.ca
>  <radius.cfg><radius_eaptest.cfg><logfile>



NB:

Have you read the reference manual ("doc/ref.html")?
Have you searched the mailing list archive (www.open.com.au/archives/ 
radiator)?
Have you had a quick look on Google (www.google.com)?
Have you included a copy of your configuration file (no secrets),
together with a trace 4 debug showing what is happening?
Have you checked the RadiusExpert wiki:
http://www.open.com.au/wiki/index.php/Main_Page

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows, MacOS X.
Includes support for reliable RADIUS transport (RadSec),
and DIAMETER translation agent.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
-
CATool: Private Certificate Authority for Unix and Unix-like systems.



--
Archive at http://www.open.com.au/archives/radiator/
Announcements on radiator-announce at open.com.au
To unsubscribe, email 'majordomo at open.com.au' with
'unsubscribe radiator' in the body of the message.


More information about the radiator mailing list