<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: trying to use webauth with a secure Active Directory in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950311#M10521</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;Typically, MD5 is used as the CHAP one-way hash function; the shared secrets are required to be&lt;BR /&gt;stored in plaintext form. &lt;BR /&gt;Microsoft has a variation of CHAP (MS-CHAP), in which the password is stored encrypted in both the peer and the authenticator. &lt;BR /&gt;&lt;BR /&gt;Therefore, MS-CHAP can take advantage of &lt;BR /&gt;irreversibly encrypted password databases commonly available, whereas the standards-based CHAP cannot.&lt;BR /&gt;&lt;BR /&gt;Good Luck !!!</description>
    <pubDate>Fri, 23 Feb 2007 14:09:57 GMT</pubDate>
    <dc:creator>Mohieddin Kharnoub</dc:creator>
    <dc:date>2007-02-23T14:09:57Z</dc:date>
    <item>
      <title>trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950306#M10516</link>
      <description>&lt;BR /&gt;We attempted to get webauth to work at our&lt;BR /&gt;site, on a 2650, using both a unix radius&lt;BR /&gt;server, and Active Directory radius server.&lt;BR /&gt;&lt;BR /&gt;It does not work for us, it seems to&lt;BR /&gt;want reversibly encrypted passwords on&lt;BR /&gt;the server.  (That would be a non starter&lt;BR /&gt;at our site.)&lt;BR /&gt;&lt;BR /&gt;The error, on Windows, is:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;Reason = The user could not be authenticated &amp;gt;using Challenge Handshake Authentication &amp;gt;Protocol (CHAP). A reversibly encrypted &amp;gt;password does not exist for this user account. &amp;gt;To ensure that reversibly encrypted passwords &amp;gt;are enabled, check either the domain password &amp;gt;policy or the password settings on the user &amp;gt;account. &lt;BR /&gt;&lt;BR /&gt;While on a simple unix radius server, it just&lt;BR /&gt;says that the radius packet does not contain&lt;BR /&gt;the password.&lt;BR /&gt;&lt;BR /&gt;Is there any way to get this to work with&lt;BR /&gt;either a unix server running any radius&lt;BR /&gt;server, or with AD running any radius server ?&lt;BR /&gt;&lt;BR /&gt;By the way, here is our switch config&lt;BR /&gt;fragment:&lt;BR /&gt;&lt;BR /&gt;radius-server host a.b.c.d key testing &lt;BR /&gt;aaa port-access web-based 47&lt;BR /&gt;aaa port-access web-based 47 redirect-url "&lt;A href="http://www.google.com" target="_blank"&gt;http://www.google.com&lt;/A&gt;"&lt;BR /&gt;&lt;BR /&gt;It shows the web login page fine, just doesn't&lt;BR /&gt;allow login.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Feb 2007 09:20:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950306#M10516</guid>
      <dc:creator>Bruce Campbell_3</dc:creator>
      <dc:date>2007-02-23T09:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950307#M10517</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;You have configured the basic commands that the WEB auth. needs to work.&lt;BR /&gt;&lt;BR /&gt;I suggest you to test authentication with some test users you create on the RADIUS, not on the active directory.&lt;BR /&gt;&lt;BR /&gt;Good Luck !!!</description>
      <pubDate>Fri, 23 Feb 2007 13:18:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950307#M10517</guid>
      <dc:creator>Mohieddin Kharnoub</dc:creator>
      <dc:date>2007-02-23T13:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950308#M10518</link>
      <description>&lt;BR /&gt;We have RADIUS working fine with 802.1x port&lt;BR /&gt;authentication, and also fine with&lt;BR /&gt;telnet/console access.  802.1x only works&lt;BR /&gt;with eap-radius, in our environment&lt;BR /&gt;with irreversible password encryption.&lt;BR /&gt;&lt;BR /&gt;What doesn't work is web auth, it seems&lt;BR /&gt;to require chap radius only.&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Feb 2007 13:25:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950308#M10518</guid>
      <dc:creator>Bruce Campbell_3</dc:creator>
      <dc:date>2007-02-23T13:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950309#M10519</link>
      <description>And your RADIUS server that is configured in your first post is EAP one or CHAP?&lt;BR /&gt;&lt;BR /&gt;Can you run: show authentication.&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Feb 2007 13:34:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950309#M10519</guid>
      <dc:creator>Mohieddin Kharnoub</dc:creator>
      <dc:date>2007-02-23T13:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950310#M10520</link>
      <description>&lt;BR /&gt;eap for 802.1x (when 802.1x was tested&lt;BR /&gt;with chap, it didn't work, as passwords&lt;BR /&gt;are irreversibly encrypted in AD).&lt;BR /&gt;&lt;BR /&gt;chap for webauth.  (webauth only supports&lt;BR /&gt;chap).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt; show auth&lt;BR /&gt;&lt;BR /&gt; Status and Counters - Authentication Information&lt;BR /&gt;&lt;BR /&gt;  Login Attempts : 3 &lt;BR /&gt;  Respect Privilege : Disabled &lt;BR /&gt;&lt;BR /&gt;              | Login      Login      Enable     Enable    &lt;BR /&gt;  Access Task | Primary    Secondary  Primary    Secondary &lt;BR /&gt;  ----------- + ---------- ---------- ---------- ----------&lt;BR /&gt;  Console     | Local      None       Local      None      &lt;BR /&gt;  Telnet      | Local      None       Local      None      &lt;BR /&gt;  Port-Access | EapRadius                                &lt;BR /&gt;  Webui       | Local      None       Local      None      &lt;BR /&gt;  SSH         | Local      None       Local      None      &lt;BR /&gt;  Web-Auth    | ChapRadius                               &lt;BR /&gt;  MAC-Auth    | ChapRadius                               &lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Fri, 23 Feb 2007 13:42:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950310#M10520</guid>
      <dc:creator>Bruce Campbell_3</dc:creator>
      <dc:date>2007-02-23T13:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950311#M10521</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Typically, MD5 is used as the CHAP one-way hash function; the shared secrets are required to be&lt;BR /&gt;stored in plaintext form. &lt;BR /&gt;Microsoft has a variation of CHAP (MS-CHAP), in which the password is stored encrypted in both the peer and the authenticator. &lt;BR /&gt;&lt;BR /&gt;Therefore, MS-CHAP can take advantage of &lt;BR /&gt;irreversibly encrypted password databases commonly available, whereas the standards-based CHAP cannot.&lt;BR /&gt;&lt;BR /&gt;Good Luck !!!</description>
      <pubDate>Fri, 23 Feb 2007 14:09:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950311#M10521</guid>
      <dc:creator>Mohieddin Kharnoub</dc:creator>
      <dc:date>2007-02-23T14:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950312#M10522</link>
      <description>&lt;BR /&gt;Procurve support has submitted a Customer&lt;BR /&gt;Enhancement Request on my behalf,&lt;BR /&gt;to support either MS-CHAP, or plain&lt;BR /&gt;RADIUS, for webauth.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 26 Feb 2007 19:02:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950312#M10522</guid>
      <dc:creator>Bruce Campbell_3</dc:creator>
      <dc:date>2007-02-26T19:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: trying to use webauth with a secure Active Directory</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950313#M10523</link>
      <description>check out 5400 code version K.12.23+ for peap-mschapv2 support on web-auth...&lt;BR /&gt;&lt;BR /&gt;this may solve your problem...&lt;BR /&gt;&lt;BR /&gt;hth...jeff</description>
      <pubDate>Wed, 28 Nov 2007 14:36:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/trying-to-use-webauth-with-a-secure-active-directory/m-p/3950313#M10523</guid>
      <dc:creator>Jeff Carrell</dc:creator>
      <dc:date>2007-11-28T14:36:13Z</dc:date>
    </item>
  </channel>
</rss>

