radius authentication

Feb 15, 2006 1 Replies

Hi all, I'm trying to use radius authentication for testing and I have observed that if I use a CHAP request with my client it overrides the secret key ( shared ): it means that I can write wrong key with correct account and the authentication WORKS.



If I use PAP method ther is no problem because I MUST put the correct shared key and authentication doesn't work with wrong key.



I think this is a normal behaviour but I cannot find this in Radius RFC.



Does anyone know if this behaviour is correct ?



thanks in advance Loris



Hi,

In case of PAP the "password" field is encrypted using the secret key. If the secret key does not match the radius server will never have the right password.

CHAP and MsChap do not use the "password" field like PAP. Hence the secret key isnt used > Hi all,

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required