[strongSwan] ikev2 eap-radius ttls pap

Thomas Will thomas.will at xinux.de
Mon Feb 9 14:20:59 CET 2015


Am 09.02.2015 um 12:18 schrieb Martin Willi:
> Hi Thomas,
>
>> is it possible to uses strongswan with eap-ttls and pap?
> EAP-TTLS in strongSwan currently supports tunneling other EAP methods
> only. PAP is not an EAP method, but a different protocol for password
> authentication. Plain (non-EAP) PAP, CHAP or MSCHAP is not supported in
> our EAP-TTLS implementation.
>
> Regards
> Martin
>
>
hello martin,

hm thats bad ... is there any chance to use the crypt posix passwords?
i don't want samba3.schema with ntlm-hashs ....
any idea?

perhaps over strongswan-plugin-xauth-pam with ldap and without radius?

regards ...


-- 
thomas will
- xinux e.K.- networking - security - consulting - training   -
- novell certified linux professional - lpi level 2 certified -
- fon 06332 44040  - fax 06332 899227  - mobil 0170 52 18 548  -
- 66482 zweibruecken - wichernstr. 18  - http://www.xinux.de  -
- Amtsgericht  -  Registergericht  -  Zweibruecken - HRA 1518 -



More information about the Users mailing list