Re: [strongSwan] ikev2 eap-radius ttls pap

2015-02-09 Thread Martin Willi
Hi Thomas,

 is it possible to uses strongswan with eap-ttls and pap?

EAP-TTLS in strongSwan currently supports tunneling other EAP methods
only. PAP is not an EAP method, but a different protocol for password
authentication. Plain (non-EAP) PAP, CHAP or MSCHAP is not supported in
our EAP-TTLS implementation.

Regards
Martin

___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users


Re: [strongSwan] ikev2 eap-radius ttls pap

2015-02-09 Thread Thomas Will

Am 09.02.2015 um 14:20 schrieb Thomas Will:

Am 09.02.2015 um 12:18 schrieb Martin Willi:

Hi Thomas,


is it possible to uses strongswan with eap-ttls and pap?

EAP-TTLS in strongSwan currently supports tunneling other EAP methods
only. PAP is not an EAP method, but a different protocol for password
authentication. Plain (non-EAP) PAP, CHAP or MSCHAP is not supported in
our EAP-TTLS implementation.

Regards
Martin



hello martin,

hm thats bad ... is there any chance to use the crypt posix passwords?
i don't want samba3.schema with ntlm-hashs 
any idea?

perhaps over strongswan-plugin-xauth-pam with ldap and without radius?

regards ...




perhaps eap-gtc?

--
thomas will
- xinux e.K.- networking - security - consulting - training   -
- novell certified linux professional - lpi level 2 certified -
- fon 06332 44040  - fax 06332 899227  - mobil 0170 52 18 548  -
- 66482 zweibruecken - wichernstr. 18  - http://www.xinux.de  -
- Amtsgericht  -  Registergericht  -  Zweibruecken - HRA 1518 -

___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users


Re: [strongSwan] ikev2 eap-radius ttls pap

2015-02-09 Thread Thomas Will

Am 09.02.2015 um 12:18 schrieb Martin Willi:

Hi Thomas,


is it possible to uses strongswan with eap-ttls and pap?

EAP-TTLS in strongSwan currently supports tunneling other EAP methods
only. PAP is not an EAP method, but a different protocol for password
authentication. Plain (non-EAP) PAP, CHAP or MSCHAP is not supported in
our EAP-TTLS implementation.

Regards
Martin



hello martin,

hm thats bad ... is there any chance to use the crypt posix passwords?
i don't want samba3.schema with ntlm-hashs 
any idea?

perhaps over strongswan-plugin-xauth-pam with ldap and without radius?

regards ...


--
thomas will
- xinux e.K.- networking - security - consulting - training   -
- novell certified linux professional - lpi level 2 certified -
- fon 06332 44040  - fax 06332 899227  - mobil 0170 52 18 548  -
- 66482 zweibruecken - wichernstr. 18  - http://www.xinux.de  -
- Amtsgericht  -  Registergericht  -  Zweibruecken - HRA 1518 -

___
Users mailing list
Users@lists.strongswan.org
https://lists.strongswan.org/mailman/listinfo/users