|
Hi...
I think that the Proxy can get
the username and password because it uses PAP.
So the Proxy could be a new NAS
to send Auth-Request (with the username and password that it got) using
CHAP.
If the reault of challenge is
"accept", the proxy will reply Access-Accept to NAS...
----- Original Message -----
Sent: Wednesday, November 19, 2003 9:12
AM
Subject: Re: Convert Auth from PAP to CHAP
???
At 03:25 18/11/2003, Allen Chung wrote:
Hello~ NAS ======>
FreeRadius(Proxy) ===========> Other Radius
Server
(PAP)
(PAP) <===>
(CHAP)
(CHAP) My Proxy Server
receives Auth-Request(PAP) from the NAS and proxy it to other Radius Server.
The
other Radius Server supports only CHAP, but the NAS uses
PAP. I hope that
FreeRadius(Proxy) could convert (PAP) to
(CHAP). Might it work and How
to setup the freeradiusd ?
I think you have a
theoretical problem here -- chap is by its nature a challenge-based
authentication scheme, whereas PAP presents a username & password up
front. I can't imagine how you could "convert" one to the
other.
Alex
|