| Article: |
A Technical Comparison of TTLS and PEAP | |
| Subject: | TTLS versus PEAP | |
| Date: | 2003-12-11 19:04:11 | |
| From: | anonymous2 | |
|
I really am entertained about those that endorse PEAP over TTLS because it is pushed by Microsoft... Sounds like a GREAT idea to me.. especially when Microsoft cannot keep viruses under control with all their vulnerabilites they have on a day by day basis.. Remember Nimda, Sobig, Welchia. For those of you endorsing PEAP because Microsoft developed it, take time to pat Microsoft on the back... I am sure those of us IT professionals who work hard cleaning up the mess caused by the viruses will appreciate it.
|
||
Showing messages 1 through 2 of 2.
-
TTLS versus PEAP
2008-07-29 16:51:49 sn555 [Reply | View]
I like to comment on one point that JMK made; user identity being passed to authenticator before the tunnel is set up. Note that this is first user ID passed, requested by (i.e) wireless AP. This userid will always be passed unencrypted but the catch is to configure, on the supplicant, this id as anonymous instead of real user id. Wireless AP won't care whether 'anonymous' or real id is received. In this sense, both PEAP and TTLS supports user identity hiding.
Just a side note, I am still going with TTLS since I have to support *nix clients.




It seems that it is a huge security issue, or maybe i am mistaking...