| Article: |
A Technical Comparison of TTLS and PEAP | |
| Subject: | Clarifications | |
| Date: | 2003-06-13 12:48:08 | |
| From: | anonymous2 | |
|
Response to: Clarifications
|
||
|
The information seems technically incorrect.
|
||
Showing messages 1 through 2 of 2.
-
MS-Chap is designed for MS Databases
2003-07-07 08:51:37 anonymous2 [Reply | View]
Here is the issue: When using the MS-CHAP or MS-CHAPv2 protocols, the Challange exchange between the RADIUS server and the supplicant are based on the NT-Hash of the users password. This means that the Database that the RADIUS server looks at needs to have access to the NT-Hash of the users password, not the clear text version of the password. This is fine if your database happens to be Active Directory, because this is how passwords are stored in AD, but if it is LDAP, or SQL, you would have to go through some process to get the NT-hash of all your users passwords into this other database. This is why EAP-MSChapv2 (and thus Micosoft's PEAP supplicant) is really only good if your database is Microsoft.
-
Clarifications
2003-06-19 00:37:34 anonymous2 [Reply | View]
MSCHAP? The guy is talking about MSCHAPv2....
Haven't seen PEAP-MSCHAP yet... :P
MSCHAPv2 needs plaint text or Microsoft NT style encrypted passwords. MSCHAPV2 uses md4 encryption.... does SQL support that? LDAP doesn't (MD5 and SHA).
PEAP machine authentication will only work in a Microsoft NT environment.
PEAP only supports inner EAP
TTLS support DIAMETER which can include:
PAP,CHAP and .... EAP.
There are two version of PEAP. MS PEAP and Cisco PEAP. MS PEAP works best with the MS IAS and Cisco PEAP works best with the ACS.
So everyone is doing their best as usuall...



