- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- peap-mschapv2 on web authentication
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-09-2008 08:56 PM
тАО10-09-2008 08:56 PM
peap-mschapv2 on web authentication
Traditionally we will need to set up supplicant / client to use an authentication protocol to forward / hash / encapsulate credentials to the authenticator in switch. In this case, there is nothing set up, so how will client (in this case internet explorer) knows that it has to use machapv2 as inside protocol and peap as outside tunnel as this is not the case of 802.1x configured supplicant.
Yes the switch in this case will send a challenge to client, when client tries to open a browser and present a window on a webpage to supply the credentials, but still the sent credentials will need to be in mschapv2 format ( both way authentication).
Doing a reserch on google does not come up with anything (other than a couple procurve references) on use of mschapv2 or peap-mschapv2 for web page authentication. Procurve documentation is not helpful as it does not explain how is a browser client supposed to use peap-mschapv2.
Any feedback will be appreciated.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 05:27 AM
тАО10-13-2008 05:27 AM
Re: peap-mschapv2 on web authentication
http://cdn.procurve.com/training/Manuals/3500-5400-6200-8200-ASG-Jan08-4-WebMacAuth.pdf
Basically, your web browser can use either unencrypted HTTP, or encrypted HTTPS between the client and the switch.
The peap-mschapv2 part is for the connection between the switch and the RADIUS server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-13-2008 11:49 AM
тАО10-13-2008 11:49 AM
Re: peap-mschapv2 on web authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-14-2008 04:48 AM
тАО10-14-2008 04:48 AM
Re: peap-mschapv2 on web authentication
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-14-2008 05:36 PM
тАО10-14-2008 05:36 PM
Re: peap-mschapv2 on web authentication
I thought CHAP or any variation of CHAP (mschap v2) will still require radius to retrieve password from say AD (which will normally store password as one way hashed MD5/ irrersible and that will fail for chap as it requires clear or reversible encryption storage) to be able to hash it with challenge received from NAS/Switch and then compared two hashes. How does mschap with peap tunneling get away with requirement of not requiring passwords to be stored on AD with reversible encryption?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-15-2008 04:16 AM
тАО10-15-2008 04:16 AM