Re: Send response to client

2011-06-27 Thread Stefan Winter
Hi, Am 27.06.2011 07:55, schrieb Christ Schlacta: is it at all possible to send a message to a windows 7 or windows vista client that the client is guaranteed to see when authentication is rejected? more details: wireless WPA2-EAP-TLS There is no such guarantee. RADIUS ends at the

Re: Send response to client

2011-06-27 Thread Fajar A. Nugraha
On Mon, Jun 27, 2011 at 12:55 PM, Christ Schlacta li...@aarcane.org wrote: is it at all possible to send a message to a windows 7 or windows vista client that the client is guaranteed to see when authentication is rejected? more details: wireless WPA2-EAP-TLS on a Ubiquiti PicoStation 2

Re: Send response to client

2011-06-27 Thread Arran Cudbard-Bell
On Jun 27, 2011, at 7:55 AM, Christ Schlacta wrote: is it at all possible to send a message to a windows 7 or windows vista client that the client is guaranteed to see when authentication is rejected? Not using EAP no. There's a special EAP-Message type of EAP-Notification which is meant to

Re: Send response to client

2011-06-27 Thread David Mitton
It's even worse than that. Windows XP and Vista supplicants will respond to an EAP notification message (after dropping it on the ground) with the appropriate acknowledgement. The first release of WIndows 7 wouldn't even do that. So if an EAP server sent a Notification message, the

Re: Send response to client

2011-06-27 Thread Arran Cudbard-Bell
ProCurve products used to encapsulate the Reply-Message in an EAP-Notification and send it after sending the EAP-Success packet. Windows and Mac clients ignored the packet (actually Macs printed the contents in one of the log files, which was kinda cool), but WPA_Supplicant took it to mean that