PEAP with Active Directory

2005-03-02 Thread Javier Jiménez Díaz
Hi all,
I've got a freeradius 1.0.1 server running fine with OpenLDAP and now I
would like to authenticate against an Active Directory server. I can do it
with TLS, but when I try to do it with PEAP, it doesn works. I read about it
and found out that should be put on radiusd.conf something with ntlm_auth
On my mschap section I have:
ntlm_auth =
/usr/bin/ntlm_auth --request-nt-key --username=%{mschap:User-Name} --domain
=%{mschap:NT-Domain} --challenge=%{mschap:Challenge:-00} --nt-response=%{msc
hap:NT-Response:-00}

And my log is attached(sorry if too long).

Does anybody know what should I do? It is possible to do what I want to?
I apologize in advance if it is very simple.
Thanks for any help!



__
Este mensaje, y en su caso, cualquier fichero anexo al mismo,
 puede contener informacion clasificada por su emisor como confidencial
 en el marco de su Sistema de Gestion de Seguridad de la 
Informacion siendo para uso exclusivo del destinatario, quedando 
prohibida su divulgacion copia o distribucion a terceros sin la 
autorizacion expresa del remitente. Si Vd. ha recibido este mensaje 
 erroneamente, se ruega lo notifique al remitente y proceda a su borrado. 
Gracias por su colaboracion.
__
This message including any attachments may contain confidential 
information, according to our Information Security Management System,
 and intended solely for a specific individual to whom they are addressed.
 Any unauthorised copy, disclosure or distribution of this message
 is strictly forbidden. If you have received this transmission in error,
 please notify the sender immediately and delete it.
__

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html


PEAP with Active Directory

2005-03-02 Thread Javier Jiménez Díaz
Sorry the log file  was not attached, here it goes.

Hi all,
I've got a freeradius 1.0.1 server running fine with OpenLDAP and now I
would like to authenticate against an Active Directory server. I can do it
with TLS, but when I try to do it with PEAP, it doesn works. I read about it
and found out that should be put on radiusd.conf something with ntlm_auth
On my mschap section I have:
ntlm_auth =
/usr/bin/ntlm_auth --request-nt-key --username=%{mschap:User-Name} --domain
=%{mschap:NT-Domain} --challenge=%{mschap:Challenge:-00} --nt-response=%{msc
hap:NT-Response:-00}

And my log is attached(sorry if too long).

Does anybody know what should I do? It is possible to do what I want to?
I apologize in advance if it is very simple.
Thanks for any help!

__
Este mensaje, y en su caso, cualquier fichero anexo al mismo,
 puede contener informacion clasificada por su emisor como confidencial
 en el marco de su Sistema de Gestion de Seguridad de la 
Informacion siendo para uso exclusivo del destinatario, quedando 
prohibida su divulgacion copia o distribucion a terceros sin la 
autorizacion expresa del remitente. Si Vd. ha recibido este mensaje 
 erroneamente, se ruega lo notifique al remitente y proceda a su borrado. 
Gracias por su colaboracion.
__
This message including any attachments may contain confidential 
information, according to our Information Security Management System,
 and intended solely for a specific individual to whom they are addressed.
 Any unauthorised copy, disclosure or distribution of this message
 is strictly forbidden. If you have received this transmission in error,
 please notify the sender immediately and delete it.
__


rad.log
Description: Binary data