Thus spake Sean Perry ([EMAIL PROTECTED]) [09/09/03 19:55]:
> >If I change the mpd configuration to use PAP instead of CHAP, I get
> >authentication success, but then there's some weirdness going on on the mpd
> >side of things that I'm also trying to figure out.
> >
> >Even though rlm_chap complains about not being able to find a proper
> >Chap-Password attribute, I can see the MS-CHAP-Challenge and -Response 
> >right
> >in the packet debug.
> 
> as I was told recently, you can't get there from here.

<sigh>

That's what I was afraid of...

> There is currently no way to authenticate via CHAP against a Windows 
> domain from Linux.  Alan explains this in the thread I started last week.

I have to do some reading up on CHAP.  Before I started this, I had
convinced myself, against my own judgement, that this would in fact be
possible.

> The best possibility I have found is using a radius relay and a Windows 
> based radius server like Internet Authentication Service which comes 
> with win2k server.  Haven't tried to get it to work yet, but it is the 
> most likely way to get it working.

Unfortunately the DC is not under my control.  I'll have to convince the
admins there to install the RADIUS server.  You don't happen to know if NT4
comes with one, do you?  </clutching at straws>

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to