EAP-TTLS configuration with PAP inner

2010-02-23 Thread Colin Byelong
Hi, Apologies if this has been asked before. I am trying to configure freeradius to replicate our current radius server, there are a couple of things that im not clear about. We tend to use a anonym...@realm identity for the EAP outer ID, in our current radius server this is defined in a

Re: EAP-TTLS configuration with PAP inner

2010-02-23 Thread Alan Buxey
Hi, We tend to use a anonym...@realm identity for the EAP outer ID, in our current radius server this is defined in a users file and has the format of anonymous Encrypted-Password=nevermatch is there a similar thing in freeradius and where should this be defined ? IIRC, this is just so

Re: EAP-TTLS configuration with PAP inner

2010-02-23 Thread Colin Byelong
Hi Thanks for the quck reply. Hi, We tend to use a anonym...@realm identity for the EAP outer ID, in our current radius server this is defined in a users file and has the format of anonymous Encrypted-Password=nevermatch is there a similar thing in freeradius and where should this be

Re: EAP-TTLS configuration with PAP inner

2010-02-23 Thread Alan Buxey
Hi, I thought it should be ttls but I found this to be a little confusing aye. there are a couple of 'default_eap_type' lines - one for the main EAP engine..and then entries under a couple of the tunnelled types (eg peap and ttls) eap { default_eap_type = ttls ... ... } is correct

Re: EAP-TTLS configuration with PAP inner

2010-02-23 Thread Colin Byelong
On 23/02/2010 10:44, Alan Buxey wrote: Hi, aye. there are a couple of 'default_eap_type' lines - one for the main EAP engine..and then entries under a couple of the tunnelled types (eg peap and ttls) eap { default_eap_type = ttls ... ... } is correct under the ttls {}

Re: EAP-TTLS configuration with PAP inner

2010-02-23 Thread Alan Buxey
Hi, This is what was confusing me I would have thought I should put ttls here but I have already defined that as the default eap type, I know that pap is not a eap-type but that what we are using in the tunnel, could I put md5 here and configure ldap in the inner-tunnel file ? yes - you