[strongSwan] EAP_MSCHAPv2 and RADIUS

2009-09-25 Thread Peter Winterer
Hello all, Currently on the strongswan wiki there is an example configuration for: EAP_MSCHAPv2 authentication with EAP identity (username and password in ipsec.secrets). My question is, can EAP_MSCHAPv2 authentication with EAP work in conjunction with a radius server (username and password is

Re: [strongSwan] EAP_MSCHAPv2 and RADIUS

2009-09-25 Thread Andreas Steffen
Hi Peter, although the FreeRADIUS server computes the MSK value in the MSCHAPv2 case, the MSK is discarded and not included it in the EAP response. Therefore FreeRADIUS cannot be used with IKEv2 EAP_MSCHAPv2. During LinuxTag 2009 we talked with a FreeRADIUS developer and he told us that the MSK